Defaults Reference
Chapter 11
Certificate Profiles
443
•
If the extension exists in a certificate, it limits the uses of the certificate to those
specified (it limits the applications for a certificate).
•
If the extension is not present, the certificate can be used for all applications except
object signing.
You can define the following constraints with this default:
•
Netscape Certificate Type Extension Constraint, see “Netscape Certificate Type
Extension Constraint,” on page 456.
•
Extension Constraint, see “Extension Constraint,” on page 454.
•
No Constraints, see “No Constraint,” on page 456.
Table 11-10
Netscape Certificate Type Extension Default Configuration Parameters
Parameter
Description
critical
Select true to mark this extension critical; select false to mark the
extension noncritical.
SSLClient
Specifies that the certificate can be used by clients for
authentication during SSL connections. Select true to include
this capability; select false to not include this capability.
SSLServer
Specifies that the certificate can be used by servers for
authentication during SSL connections. Select true to include
this capability; select false to not include this capability.
CertEmail
Specifies that the certificate can be used to send secure email
messages. Select true to include this capability; select false to not
include this capability.
CertObjectSigning
Specifies that the certificate can be used for signing objects such
as Java applets and plug-ins. Select true to include this
capability; select false to not include this capability.
CertSSLCA
Specifies that the certificate can be used by a CA to issue
certificates for SSL connections. Select true to include this
capability; select false to not include this capability.
CertEmailCA
Specifies that the certificate can be used by a CA to issue
certificates for secure email. Select true to include this
capability; select false to not include this capability.
CertObjectSigningCA
Specifies that the certificate can be used by a CA to issue
certificates for object signing. Select true to include this
capability; select false to not include this capability.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...