Re: RFC 5280 Extended Key Usage - explanation
Russ Housley <[email protected]> Mon, 20 Nov 2023 14:00:27 -0500
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
There is a document-signing extended key usage defined in RFC 9336 to resolve this ambiguity. Russ > On Nov 13, 2023, at 2:27 AM, Peter Miškovič <[email protected]> wrote: > > Hello > > I want to ask you for an explanation of this part of RFC5280: > > 4.2.1.12. Extended use of the key > > "If a certificate contains both a key usage extension and an extended key usage extension, then both extensions MUST be processed independently and the certificate MUST only be used for a purpose consistent with both extensions." > > Means this that if I have the "digitalSignature" extension in the Key Usage certificate and the "id-kp-clientAuth" extension in the Extended Key Usage extension, I can use such certificate for TLS WWW client authentication only and not for digitally signing documents, for example PDF? > > Or it can be understood that I can use such certificate only for digitally signing or TLS WWW client authentication, but not for anything else, e.g. Email protection, code signing? > > What does "then both extensions MUST be processed independently" mean, if I should take into account their common connection as a result? > > Thank you in advance. > > Regards > Peter Miskovic > --------------------------------- > Peter Miskovic > CA Chief Operating Officer > > Disig, a.s. > Zahradnicka 151, 821 08 Bratislava 2, Slovakia > > phone +421 2 208 50 150 > cell phone +421 905 960 345 > [email protected] <mailto:[email protected]> > www.disig.sk <http://www.disig.sk/>_______________________________________________ > pkix mailing list > [email protected] <mailto:[email protected]> > https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix