11.07.2015 Views

Internet X.509 Public Key Infrastructure (PKI) Proxy ... - Clizio.com

Internet X.509 Public Key Infrastructure (PKI) Proxy ... - Clizio.com

Internet X.509 Public Key Infrastructure (PKI) Proxy ... - Clizio.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

RFC 3820 <strong>X.509</strong> <strong>Proxy</strong> Certificate Profile June 20044.1.6. OutputsIf path processing succeeds, the procedure terminates, returning asuccess indication together with final value of theworking_public_key, the working_public_key_algorithm, theworking_public_key_parameters, and the proxy_policy_list.4.2. Using the Path Validation AlgorithmEach <strong>Proxy</strong> Certificate contains a <strong>Proxy</strong>CertInfo extension, whichalways contains a policy language OID, and may also contain a policyOCTET STRING. These policies serve to indicate the desire of eachissuer in the proxy certificate chain, starting with the EEC, todelegate some subset of their rights to the issued proxy certificate.This chain of policies is returned by the algorithm to theapplication.The application MAY make authorization decisions based on the subjectdistinguished name of the proxy certificate or on one of the proxycertificates in it’s issuing chain or on the EEC that serves as theroot of the chain. If an application chooses to use the subjectdistinguished name of a proxy certificate in the issuing chain or theEEC it MUST use the returned policies to restrict the rights itgrants to the proxy certificate. If the application does not knowhow to parse any policy in the policy chain it MUST not use, for thepurposes of making authorization decisions, the subject distinguishedname of any certificate in the chain prior to the certificate inwhich the unrecognized policy appears.Application making authorization decisions based on the contents ofthe proxy certificate key usage or extended key usage extensions MUSTexamine the list of key usage, extended key usage and proxy policiesresulting from proxy certificate path validation and determine theeffective key usage functions of the proxy certificate as follows:* If a certificate is a proxy certificate with a proxy policy ofid-ppl-independent or an end entity certificate, the effective keyusage functions of that certificate is as defined by the key usageand extended key usage extensions in that certificate. The keyusage functionality of the issuer has no bearing on the effectivekey usage functionality.* If a certificate is a proxy certificate with a policy other thanid-ppl-independent, the effective key usage and extended key usagefunctionality of the proxy certificate is the intersection of thefunctionality of those extensions in the proxy certificate and theeffective key usage functionality of the proxy issuer.Tuecke, et al. Standards Track [Page 23]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!