12.07.2015 Views

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6666676686696706716726736746756763.15 Certificate IssuerThis attribute is deprecated as of version <strong>1.1</strong> of this specification and MAY be removed from subsequentversions of this specification. The X.509 Certificate Issuer attribute (see Section 3.12) SHOULD be usedinstead.The Certificate Issuer attribute is a structure (see Table 67) used to identify the issuer of a certificate,containing the Issuer Distinguished Name (i.e., from the Issuer field of the certificate). It MAY include oneor more alternative names (e.g., email address, IP address, DNS name) for the issuer of the certificate(i.e., from the Issuer Alternative Name extension within the certificate). The server SHALL set thesevalues based on the information it extracts from a certificate that is created as a result of a Certify or aRe-certify operation or is sent as part of a Register operation. These values SHALL NOT be changed ordeleted before the object is destroyed.Certificate IssuerObject Encoding REQUIREDCertificate IssuerDistinguished NameCertificate IssuerAlternative NameStructureText StringText StringYesNo, MAY be repeated677Table 66: Certificate Issuer Attribute StructureSHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesYesServerNoNoNoNoRegister, Certify, Re-certifyCertificates678679680681682683Table 67: Certificate Issuer Attribute Rules3.16 Digital Signature AlgorithmThe Digital Signature Algorithm identifies the digital signature algorithm associated with a digitally signedobject (e.g., Certificate). This attribute SHALL be set by the server when the object is created orregistered and then SHALL NOT be changed or deleted before the object is destroyed.ObjectEncodingDigital Signature Algorithm Enumeration, see 9.1.3.2.7684Table 68: Digital Signature Algorithm Attributekmip-spec-v<strong>1.1</strong>-cos01 21 September 2012Standards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 42 of 164

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!