Appendix B. Defaults, Constraints, and Extensions for Certificates and CRLs
454
Parameter
Description
from being set; select a hyphen,
-
, to indicate no
constraints are placed for this parameter.
nonRepudiation
Specifies whether to set S/MIME signing
certificates. Select
true
to allow this to be set;
select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed
for this parameter.
WARNING
Using this bit is controversial.
Carefully consider the legal
consequences of its use before
setting it for any certificate.
keyEncipherment
Specifies whether to set the extension for SSL
server certificates and S/MIME encryption
certificates. Select
true
to allow this to be set;
select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed
for this parameter.
dataEncipherment
Specifies whether to set the extension when the
subject's public key is used to encrypt user data,
instead of key material. Select
true
to allow this
to be set; select
false
to keep this from being
set; select a hyphen,
-
, to indicate no constraints
are placed for this parameter.
keyAgreement
Specifies whether to set the extension whenever
the subject's public key is used for key
agreement. Select
true
to allow this to be set;
select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed
for this parameter.
keyCertsign
Specifies whether the extension applies for all
CA signing certificates. Select
true
to allow this
to be set; select
false
to keep this from being
set; select a hyphen,
-
, to indicate no constraints
are placed for this parameter.
cRLSign
Specifies whether to set the extension for CA
signing certificates that are used to sign CRLs.
Select
true
to allow this to be set; select
false
to keep this from being set; select a hyphen,
-
, to indicate no constraints are placed for this
parameter.
encipherOnly
Specifies whether to set the extension if the
public key is to be used only for encrypting data.
If this bit is set,
keyAgreement
should also be
set. Select
true
to allow this to be set; select
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...