Constraints Reference
Chapter 11
Certificate Profiles
455
Key Usage Extension Constraint
The key usage extension constraint checks if the key usage constraint in the certificate
request satisfies the criteria set in this constraint.
Table 11-20
Key Constraint Configuration Parameters
Parameter
Description
Type
Select which key type is allowed from DSA and RSA.
MinLength
Specifies the minimum allowable key length.
MaxLength
Specifies the maximum allowable key length.
Table 11-21
Key Usage Extension Constraint Configuration Parameters
Parameter
Description
critical
Select true allow this extension to be marked critical; select false to
keep this extension from being marked critical. Select true to allow this
to be set; select false to not allow this to be set; select
“-”
to indicate
no constraints are placed for this parameter.
digitalSignature
Specifies whether to allow for signing of SSL client certificates,
S/MIME signing certificates, and object-signing certificates.
Select
true to allow this to be set; select false to not allow this to be set; select
“-”
to indicate no constraints are placed for this parameter.
nonRepudiation
Specifies whether some S/MIME signing certificates and
object-signing certificates. Note, however, that the use of this bit is
controversial. You should carefully consider the legal consequences of
its use before setting it for any certificate. Select true to allow this to be
set; select false to not allow this to be set; select
“-”
to indicate no
constraints are placed for this parameter.
keyEncipherment
Specifies whether to set the extension for SSL server certificates and
S/MIME encryption certificates. Select true to allow this to be set;
select false to not allow this to be set; select
“-”
to indicate no
constraints are placed for this parameter.
dataEncipherment
Specifies whether to set the extension when the subjects’s public key is
used to encipher user data (as opposed to key material). Select true to
allow this to be set; select false to not allow this to be set; select
“-”
to
indicate no constraints are placed for this parameter.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...