18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6.1.7 <strong>Key</strong> Usage Purposes (as per X.509 v3 key usage field)<br />

The use of a specific key is determined by the key usage extension in the X.509 certificate. In<br />

particular, certificates to be used for digital signatures (including authentication) shall set the<br />

digitalsignature and nonrepudiation bits.<br />

<strong>Certificate</strong>s to be used for encryption shall set the keyEncipherment bit.<br />

<strong>Certificate</strong>s to be used for key agreement shall set the keyAgreement bit.<br />

CA certificates shall set cRLSign and CertSign bits.<br />

<strong>Public</strong> keys that are bound into certificates shall be certified for use in signing or encrypting, but<br />

not both. This restriction is not intended to prohibit use of protocols (like the Secure Sockets<br />

Layer) that provide authenticated connections using key management certificates and require<br />

setting both digitalsignature and keyEncipherment bits to be set.<br />

62 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!