McAfee MEJCAE-AM-DA Product Guide - Page 53

Specifying certificate attributes, Attribute Name, Description

Page 53 highlights

Working with X.509 Certificates Common X.509 options The following information appears: The issuer's DN Signed Key : Scott Tibson Signed User ID: Scott Tibson Signed Key ID : 0x196DE730 (0xFBC4D3B5196DE730) Name: CN=Scott Tibson, [email protected], O=McAfee, OU=EBS Issuer: CN=Root CA, [email protected] Signer Key ID: 0xD7C74275 (0x03534DC9D7C74275) Type: X.509 Exportable: Yes Created: 2001-06-01 Expires: 2002-06-01 Last CRL: N/A Next CRL: N/A The issuer assigned serial number Trust Depth: Serial Number: 0 9170E2A076CF0C8B4938 Specifying certificate attributes When you request an X.509 certificate from a public Certificate Authority (CA), or when you issue an X.509 certificate using E-Business Server, you can include certificate attributes, additional bits of information about the certificate that may be added to the certificate as per the CA's certification policies. To add certificate attributes to the certificate you are requesting or creating, include the --cert-attribute modifier. Valid X.509 attributes include-but are not limited to-the email address of the certificate holder (E), the name of the company to which the certificate belongs (O), the unit or group within the company to which the certificate belongs (OU), and the location of the company to which the certificate belongs (L). Certificate attributes are entered in name=value format. Name represents the type of attribute you want to define such as E, O, OU, or L. You can enter the complete attribute name (as one word, without any spaces) or the abbreviated version of the attribute name. Value represents your definition for the corresponding attribute. If the value contains spaces, then you must enclose it in quotes. For example, O="McAfee" indicates that the organization that owns the certificate is McAfee. You can list several certificate attributes when requesting or creating X.509 certificates. Simply precede each name=value pair with --cert-attribute. The attributes used on certificates is a policy decision of the CA. Typically, the following attributes are used for X.509 certificates. Attribute Name: CN (Common Name) E (EMAIL) O (Organization) OU (Organizational Unit) L (Locality) STREET ST (State) Description: Often a description of the type of certificate (e.g., "Root"). The email address for the certificate holder. Typically the name of the company to which the certificate belongs (e.g.,"Secure Company"). The department or group within the company to which the certificate belongs (e.g.,"Accounting"). The location of the holder of the certificate (e.g., "Santa Clara"). The street address of the holder of the certificate. The state of the holder of the certificate (e.g., "CA"). 51 E-Business Server™ 8.6 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

51
E-Business Server
8.6
Product Guide
Working with X.509 Certificates
Common X.509 options
The following information appears:
Signed Key
: Scott Tibson <[email protected]>
Signed User ID: Scott Tibson <[email protected]>
Signed Key ID : 0x196DE730 (0xFBC4D3B5196DE730)
Serial Number:
Specifying certificate attributes
When you request an X.509 certificate from a public Certificate Authority (CA), or when you issue an X.509
certificate using E-Business Server, you can include certificate attributes, additional bits of information about
the certificate that may be added to the certificate as per the CA’s certification policies.
To add certificate attributes to the certificate you are requesting or creating, include the
--cert-attribute
modifier. Valid X.509 attributes include—but are not limited to—the email address of the certificate holder
(E), the name of the company to which the certificate belongs (O), the unit or group within the company to
which the certificate belongs (OU), and the location of the company to which the certificate belongs (L).
Certificate attributes are entered in
name=value
format.
Name
represents the type of attribute you want to
define such as E, O, OU, or L. You can enter the complete attribute name (as one word, without any spaces)
or the abbreviated version of the attribute name.
Value
represents your definition for the corresponding
attribute. If the value contains spaces, then you must enclose it in quotes. For example, O=”McAfee”
indicates that the organization that owns the certificate is McAfee. You can list several certificate attributes
when requesting or creating X.509 certificates. Simply precede each name=value pair with
--cert-attribute
.
The attributes used on certificates is a policy decision of the CA. Typically, the following attributes are used
for X.509 certificates.
Name:
CN=Scott Tibson, [email protected], O=McAfee, OU=EBS
Issuer:
CN=Root CA, [email protected]
Signer Key ID:
0xD7C74275 (0x03534DC9D7C74275)
Type:
X.509
Exportable:
Yes
Created:
2001-06-01
Expires:
2002-06-01
Last CRL:
N/A
Next CRL:
N/A
Trust Depth:
0
9170E2A076CF0C8B4938
Attribute Name:
Description:
CN (Common Name)
Often a description of the type of certificate (e.g., “Root”).
E (EMAIL)
The email address for the certificate holder.
O (Organization)
Typically the name of the company to which the certificate belongs
(e.g.,“Secure Company”).
OU (Organizational Unit)
The department or group within the company to which the certificate
belongs (e.g.,“Accounting”).
L (Locality)
The location of the holder of the certificate (e.g., “Santa Clara”).
STREET
The street address of the holder of the certificate.
ST (State)
The state of the holder of the certificate (e.g., “CA”).
The issuer’s
DN
The issuer
assigned
serial
number