26.10.2012 Views

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

224 INTERNET SECURITY<br />

Certificate fields Interpretation of contents<br />

Version Version of certificate format<br />

Serial number Certificate serial number<br />

Signature algorithm<br />

Signature algorithm identifier<br />

for certificate issuer’s signature<br />

Issuer CA’s X.500 name<br />

Validity period Start and expiry dates/times<br />

Subject name Subject X.500 name<br />

Subject public-key information<br />

Algorithm identifier and subject publickey<br />

value<br />

Issuer’s signature Certificate Authority’s digital signature<br />

Figure 6.13 X.509 version 1 certificate format.<br />

• Signature: The algorithm used by the issuer in order to sign the certificate is specified.<br />

The signature field contains the algorithm identifier for the algorithm used to sign the<br />

certificate.<br />

• Issuer: This field provides a globally unique identifier of the authority signing the<br />

certificate. The syntax of the issuer name is an X.500 distinct name. This field contains<br />

the X.500 name of the issuer that generated and signed the certificate. The DN is<br />

composed of attribute type–attribute value pairs.<br />

• Validity: This field denotes the start and expiry dates/times for the certificate. The<br />

validity field indicates the dates on which the certificate becomes valid (not before)<br />

and on which the certificate ceases to be valid (not after). In other words, it contains<br />

two time and date indications that denote the start and the end of the time period for<br />

which the certificate is valid. The validity field always uses UTCTime (Coordinated<br />

Universal Time) which is expressed in Greenwich Mean Time (Zulu).<br />

• Subject: The purpose of the subject field is to provide a unique identifier of the subject<br />

of the certificate. The syntax of the subject name will be an X.500 DN. This field<br />

contains the name of the entity for whom the certificate is being generated. The field<br />

denotes the X.500 name of the holder of the private key, for which the corresponding<br />

public key is being certified.<br />

• Subject public-key information: This field contains the value of a public key of the<br />

subject together with an identifier of the algorithm with which this public key is to<br />

be used. It includes the subject public-key field and an algorithm identifier field with<br />

algorithm and parameters subfields.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!