Re: RFC 5280 Extended Key Usage - explanation

Russ Housley <[email protected]> Mon, 20 Nov 2023 14:00:27 -0500
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
There is a document-signing extended key usage defined in RFC 9336 to resolve this ambiguity.

Russ


> On Nov 13, 2023, at 2:27 AM, Peter Miškovič <[email protected]> wrote:
> 
> Hello
>  
> I want to ask you for an explanation of this part of RFC5280:
>  
> 4.2.1.12. Extended use of the key
>  
> "If a certificate contains both a key usage extension and an extended key usage extension, then both extensions MUST be processed independently and the certificate MUST only be used for a purpose consistent with both extensions."
>  
> Means this that if I have the "digitalSignature" extension in the Key Usage certificate and the "id-kp-clientAuth" extension in the Extended Key Usage extension, I can use such certificate for TLS WWW client authentication only and not for digitally signing documents, for example PDF?
>  
> Or it can be understood that I can use such certificate only for digitally signing or TLS WWW client authentication, but not for anything else, e.g. Email protection, code signing?
>  
> What does "then both extensions MUST be processed independently" mean, if I should take into account their common connection as a result?
>  
> Thank you in advance.
>  
> Regards
> Peter Miskovic
> ---------------------------------
> Peter Miskovic
> CA Chief Operating Officer
>  
> Disig, a.s.
> Zahradnicka 151, 821 08 Bratislava 2, Slovakia
>  
> phone  +421 2 208 50 150
> cell phone +421 905 960 345
> [email protected] <mailto:[email protected]>
> www.disig.sk <http://www.disig.sk/>_______________________________________________
> pkix mailing list
> [email protected] <mailto:[email protected]>
> https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix