X.509 Version 3 Certificate: Validity Period
X.509 Version 3 Certificate: Validity Period
31
Subject Unique
Identifier: Optional
information (bit string)
for uniquely identifying
the subject, when
necessary.
33
34
X.509 Version 3 Certificate
Certification Authority's
Digital Signature: The CA's
digital signature of all the
previous fields, which is
created as the last step in
generating the certificate.
(Called Encrypted)
35
3 extension categories
Key and policy information
36
X.509 Extensions: Key and Policy
Subject and issuer keys information
Indicators of certificate policy
Extension fields
Authority key identifier (to differentiate keys of the same
CA)
Subject key identifier (to differentiate keys of the same
subject)
Key usage (bit string for 9 possibilities, such as key and/or
data encryption, signature verification on
certificates/CRLs, …)
Private-key usage period (for signatures)
Certificate policies (used for issuing and for certificate
usage)
Policy mappings (from CA to CA, for matching policies of
different CAs)
37
X.509 Extensions:
Certificate Subject Attributes
Alternate names for either the certificate
subject or the certificate issuer
Extension fields
Subject alternative name (additional
identities to be bound to the subject)
Issuer alternative name (to associate, e.g.,
internet style identities to issuer)
Subject directory attributes (such as DoB
or clearance, to be used by X.500 directory )
38
X.509 Extensions:
Certification Path Constraints
Provide constraints for certificates issued
by CAs for other CAs.
Extension fields
Basic constraints (can subject be CA and
length of allowed certification path from this CA)
Name constraints (name space for allowed
subjects in subsequent certificates)
Policy constraints (for path validation, either
prohibiting or requiring policy)
39