RFC 2459:Internet X.509 Public Key Infrastructure ...
RFC-Ref

profile


Click on the red underlined text to get to the source

... This specification profiles the format and semantics of certificates ...
... The specification profiles the X.509 version 3 certificate ...
... certificate revocation list (CRL) in Section 5. The profiles include the identification of ISO/IEC/ITU and ...
... ANSI extensions which may be useful in the Internet PKI. The profiles are presented in the 1988 Abstract Syntax Notation One (ASN.1 ...


... The goal of this specification is to develop a profile to facilitate the use of X.509 certificates within Internet applications ...
... and IPsec. In order to relieve some of the obstacles to using X.509 certificates, this document defines a profile to promote the development of certificate management ...
... Some communities will need to supplement, or possibly replace, this profile in order to meet the requirements of specialized application domains ...
... topology, especially users of secure electronic mail. This profile supports users without high bandwidth, real-time ...
... IP connectivity, or high connection availability. In addition, the profile allows for the presence of firewall or other filtered communication. ...
... This profile does not assume the deployment of an X.500 Directory system. The profile ...
... profile does not assume the deployment of an X.500 Directory system. The profile does not prohibit the use of an X.500 Directory, but other means of distributing certificates ...
... IPsec within a router. This profile recognizes the limitations of the platforms these users employ and the limitations in sophistication and attentiveness of the users themselves. This manifests itself in minimal user ...
... As with user expectations, the Internet PKI profile is structured to support the individuals who generally operate CAs. Providing ...


... X.509 v3 systems for Internet use, it is necessary to specify a profile for use of the X.509 v3 extensions tailored for the Internet ...
... X.509 v3 extensions tailored for the Internet. It is one goal of this document to specify a profile for Internet WWW, electronic mail ...
... IPsec applications. Environments with additional requirements may build on this profile or may replace it. ...
... format needs to be profiled for Internet use. It is one goal of this document to specify that profile. However, this profile does not require CAs ...
... Internet use. It is one goal of this document to specify that profile. However, this profile does not require CAs to issue CRLs ...


... Certificate and Certificate Extensions Profile ...
... This section presents a profile for public key certificates that will foster interoperability ...
... version of the encoded certificate. When extensions are used, as expected in this profile, use X.509 version 3 ...
... version 2 certificates is not expected by implementations based on this profile. ...
... distinguished names are irrelevant. The characters themselves are compared without regard to encoding. Implementations of the profile are permitted to use the comparison algorithm ...
... CAs conforming to this profile MUST always encode certificate validity ...
... For the purposes of this profile, UTCTime values MUST be expressed Greenwich Mean Time ...
... For the purposes of this profile, GeneralizedTime values MUST be expressed Greenwich Mean Time (Zulu) and MUST include seconds (i.e., ...
... subject and/or issuer names over time. This profile recommends that names not be reused for different entities and that Internet certificates ...
... use of unique identifiers. CAs conforming to this profile SHOULD NOT generate certificates with unique identifiers ...
... certificates with unique identifiers. Applications conforming to this profile SHOULD be capable of parsing unique identifiers and making comparisons. ...
... At a minimum, applications conforming to this profile MUST recognize the extensions which must or may be critical in this specification. ...
... In addition, this profile RECOMMENDS application support for the authority and subject ...
... This profile recommends support for the key identifier method by all ...
... This profile does not restrict the combinations of bits that may be set in an instantiation of the keyUsage extension. However, ...
... This profile recommends against the use of this extension. CAs conforming to this profile ...
... profile recommends against the use of this extension. CAs conforming to this profile MUST NOT generate certificates with critical ...
... times specified by the two components, respectively. CAs conforming to this profile MUST NOT generate certificates with private key usage ...
... To promote interoperability, this profile RECOMMENDS that policy information terms consist of only an OID. Where an OID ...
... OID. Where an OID alone is insufficient, this profile strongly recommends that use of qualifiers be limited to those identified in this section. ...
... IA5String. While an empty string is a valid IA5String, such an rfc822Name is not permitted by this profile. The behavior of clients that encounter such a certificate ...
... that encounter such a certificate when processing a certificication path is not defined by this profile. ...
... The subject directory attributes extension is not recommended as an essential part of this profile, but it may be used in local environments. This extension MUST be non-critical. ...
... Within this profile, the minimum and maximum fields are not used with any name forms, thus minimum is always zero, and maximum is always absent. ...
... clients that encounter a null policy constraints field is not addressed in this profile. ...
... The following key usage purposes are defined by this profile: ...
... CRL information is obtained. The extension SHOULD be non-critical, but this profile recommends support for this extension by CAs and applications. ...
... This profile defines one OID for accessMethod. The id-ad-caIssuers ...


... CRL and CRL Extensions Profile ...
... As described above, one goal of this X.509 v2 CRL profile is to foster the creation of an interoperable and reusable Internet PKI ...
... broader spectrum of operational and assurance requirements. This profile establishes a common baseline for generic applications requiring broad interoperability. The profile ...
... profile establishes a common baseline for generic applications requiring broad interoperability. The profile defines a baseline set of information that can be expected in every CRL. Also, the profile ...
... profile defines a baseline set of information that can be expected in every CRL. Also, the profile defines common locations within the CRL for frequently used ...
... This profile does not define any private Internet CRL extensions or ...
... Environments with additional or special purpose requirements may build on this profile or may replace it. ...
... CA has not revoked any unexpired certificates that it has issued. The profile requires conforming CAs to use the CRL extension cRLNumber in all CRLs ...
... version of the encoded CRL. When extensions are used, as required by this profile, this field MUST be present and MUST specify version 2 (the integer value ...
... CAs conforming to this profile that issue CRLs MUST encode thisUpdate as UTCTime ...
... UTCTime for dates through the year 2049. CAs conforming to this profile that issue CRLs MUST encode thisUpdate as GeneralizedTime for dates in the year 2050 or later. ...
... This profile requires inclusion of nextUpdate in all CRLs issued by conforming CAs ...
... clients processing CRLs which omit nextUpdate is not specified by this profile. ...
... CAs conforming to this profile that issue CRLs MUST encode nextUpdate as UTCTime ...
... UTCTime for dates through the year 2049. CAs conforming to this profile that issue CRLs MUST encode nextUpdate as GeneralizedTime for dates in the year 2050 or later. ...
... supersedes another CRL. CAs conforming to this profile MUST include this extension in all CRLs. ...


... unique identifier fields or private critical extensions, as recommended within this profile. However, if these components appear in certificates, they MUST be processed. Finally, policy qualifiers ...


... This section describes cryptographic algorithms which may be used with this profile. The section describes one-way hash functions and digital signature ...
... MD2 and MD5 are included in this profile. ...
... A patent statement regarding the RSA algorithm can be found at the end of this profile. ...
... The RSA algorithm is named for its inventors: Rivest, Shamir, and Adleman. This profile includes three signature algorithms based on ...
... A patent statement regarding the DSA can be found at the end of this profile. ...
... Certificates described by this profile may convey a public key for any public key algorithm ...
... The Diffie-Hellman OID supported by this profile is defined by ANSI X9.42 [X9.42 ...
... DSS). The DSA OID supported by this profile is ...



Google
Web
RFC-Ref