1 Authority key identifiers are required elements in end entity certificates to properly establish the trust chain.
2 Required if the same identity certificate is used when the server is acting as a client.
3 For the 96xx endpoints, PPM is defined as an IP address so PPM certificates must contain the IP:{ip} Subject Alternative Name entry when these endpoints are part of the solution.
4 URLs and DNs used to identify the location of CRLs in LDAP directories may be quite complex; entities configuring or consuming these must be able to handle characters as defined by the LDAP URI specification in RFC 4516.