You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
However, 1.3.6.1.4.1.11129.2.4.4 is not extension ID, but a key purpose ID (ExtendedKeyUsage), as specified in RFC 6962:
o a special-purpose (CA:true, Extended Key Usage: Certificate
Transparency, OID 1.3.6.1.4.1.11129.2.4.4) Precertificate Signing
Certificate. The Precertificate Signing Certificate MUST be
directly certified by the (root or intermediate) CA certificate
that will ultimately sign the end-entity TBSCertificate yielding
the end-entity certificate (note that the log may relax standard
validation rules to allow this, so long as the issued certificate
will be valid),
Thus, a new entry shall be added to "Figure 12: C509 Extended Key Usages", e.g. as follows:
In Table "Figure 8: C509 Extensions and CSR Attributes" of draft -09:
However,
1.3.6.1.4.1.11129.2.4.4
is not extension ID, but a key purpose ID (ExtendedKeyUsage), as specified in RFC 6962:Thus, a new entry shall be added to "Figure 12: C509 Extended Key Usages", e.g. as follows:
And the entry
Precertificate Signing Certificate (code 37)
in Figure 8 shall be replaced by another OID (with ending 2.4.3 instead 2.4.4):The text was updated successfully, but these errors were encountered: