12.07.2015 Views

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6256266276286296306316323.12 X.509 Certificate IssuerThe X.509 Certificate Issuer attribute is a structure (see Table 64) used to identify the issuer of a X.509certificate, containing the Issuer Distinguished Name (i.e., from the Issuer field of the X.509 certificate). ItMAY include one or more alternative names (e.g., email address, IP address, DNS name) for the issuer ofthe certificate (i.e., from the Issuer Alternative Name extension within the X.509 certificate). The serverSHALL set these values based on the information it extracts from a X.509 certificate that is created as aresult of a Certify or a Re-certify operation or is sent as part of a Register operation. These values SHALLNOT be changed or deleted before the object is destroyed.Object Encoding REQUIREDX.509 Certificate Issuer StructureIssuer DistinguishedNameIssuer AlternativeNameByte StringByte StringYesNo, MAY be repeated633Table 60: X.509 Certificate Issuer Attribute StructureSHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesYesServerNoNoNoNoRegister, Certify, Re-certifyX.509 Certificates634635636637638639640641642643644Table 61: X.509 Certificate Issuer Attribute Rules3.13 Certificate IdentifierThis attribute is deprecated as of version <strong>1.1</strong> of this specification and MAY be removed from subsequentversions of this specification. The X.509 Certificate Identifier attribute (see Section 3.10) SHOULD beused instead.The Certificate Identifier attribute is a structure (see Table 62) used to provide the identification of acertificate. For X.509 certificates, it contains the Issuer Distinguished Name (i.e., from the Issuer field ofthe certificate) and the Certificate Serial Number (i.e., from the Serial Number field of the certificate). ForPGP certificates, the Issuer contains the OpenPGP <strong>Key</strong> ID of the key issuing the signature (the signaturethat represents the certificate). The Certificate Identifier SHALL be set by the server when the certificate iscreated or registered and then SHALL NOT be changed or deleted before the object is destroyed.Certificate IdentifierObject Encoding REQUIREDStructureIssuer Text String YesSerial Number Text String Yes (for X.509 certificates) / No(for PGP certificates since theydo not contain a serial number)645Table 62: Certificate Identifier Attribute Structurekmip-spec-v<strong>1.1</strong>-cos01 21 September 2012Standards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 40 of 164

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!