423
Appendix B. Defaults, Constraints, and
Extensions for Certificates and CRLs
This appendix explains both the standard certificate extensions defined by X.509 v3 and the
extensions defined by Netscape that were used in versions of products released before X.509 v3
was finalized. It provides recommendations for extensions to use with specific kinds of certificates,
including PKIX Part 1 recommendations.
IMPORTANT
This appendix is a reference for defaults, constraints, and certificate and CRL extensions
that are used or are configurable in Red Hat Certificate System. For a complete reference
and explanation of certificate and CRL extensions, see
RFC 3280
1
.
This appendix contains the following sections:
•
Section B.1, “Defaults Reference”
•
Section B.2, “Constraints Reference”
•
Section B.3, “Standard X.509 v3 Certificate Extension Reference”
•
Section B.4, “CRL Extensions”
B.1. Defaults Reference
Defaults are used to define the contents of a certificate. This section lists and defines the predefined
defaults.
B.1.1. Authority Info Access Extension Default
This default attaches the Authority Info Access extension. This extension specifies how an application
validating a certificate can access information, such as online validation services and CA policy data,
about the CA that has issued the certificate. This extension should not be used to point directly to
the CRL location maintained by a CA; the CRL Distribution Points extension,
Section B.1.4, “CRL
Distribution Points Extension Default”
, provides references to CRL locations.
For general information about this extension, see
Section B.3.1, “authorityInfoAccess”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section B.2.3, “Extension Constraint”
.
• No Constraints; see
Section B.2.6, “No Constraint”
.
This default can define up to five locations, with parameters for each location. The parameters are
marked with an
n
in the table to show with which location the parameter is associated.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to mark the extension noncritical.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...