Extended Key Usage Extension Default
429
Parameter
Description
the IPv6 address separated by colons and
the netmask separated by periods. For
example,
0:0:0:0:0:0:13.1.68.3
,
FF01::43
,
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:255.255.255.0
,
and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:0000
.
• For
OIDName
, the value must be a unique,
valid OID specified in dot-separated
numeric component notation. For example,
1.2.3.4.55.6.5.99
.
•
OtherName
is used for names with any other
format; this supports
PrintableString
,
IA5String
,
UTF8String
,
BMPString
,
Any
,
and
KerberosName
.
PrintableString
,
IA5String
,
UTF8String
,
BMPString
,
and
Any
set a string to a base-64 encoded
file specifying the subtree, such as
/
var/lib/pki-ca/othername.txt
.
KerberosName
has the format
Realm|
NameType|NameStrings
, such as
realm1|0|
userID1,userID2
.
OtherName
must have the format
(type)oid,string
. For example,
(IA5String)1.2.3.4,MyExample
.
The value for this parameter must correspond to
the value in the
issuerName
field.
Table B.3. CRL Distribution Points Extension Configuration Parameters
B.1.5. Extended Key Usage Extension Default
This default attaches the Extended Key Usage extension to the certificate.
For general information about this extension, see
Section B.3.6, “extKeyUsage”
.
The extension identifies the purposes, in addition to the basic purposes indicated in the Key Usage
extension, for which the certified public key may be used. For example, if the key usage extension
identifies a signing key, the Extended Key Usage extension can narrow the usage of the key for only
signing OCSP responses or only Java
™
applets.
Usage
OID
Server authentication
1.3.6.1.5.5.7.3.1
Client authentication
1.3.6.1.5.5.7.3.2
Code signing
1.3.6.1.5.5.7.3.3
1.3.6.1.5.5.7.3.4
IPsec end system
1.3.6.1.5.5.7.3.5
IPsec tunnel
1.3.6.1.5.5.7.3.6
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...