Generate the Security Module HTTP identity certificate with the following X509v3 extensions and attributes.
|
Attribute
|
Value
|
Required
|
|
Subject
|
CN={breeze-fqdn}
|
Required
|
|
Validity
|
validity period
|
Required
|
|
Authority Key Identifier
|
hash
|
Required
|
|
Subject Key Identifier
|
hash
|
Recommended
|
|
Key Usage
|
digitalSignature
|
Required
|
|
nonrepudiation
|
Required
|
|
keyEncipherment
|
Required Authority key identifiers are required elements in end entity certificates to properly establish the trust chain.
|
|
Extended Key Usage
|
id-kp-serverAuth = 1.3.6.1.5.5.7.3.3.1
|
Required
|
|
id-kp-clientAuth = 1.3.6.1.5.5.7.3.3.2
|
Optional Required if the same identity certificate is used when the server is acting as a client.
|
|
Subject Alternative Name
|
IP:{breeze-security-module-ip}
|
Required For the 96xx endpoints, PPM is defined as an IP address so PPM certificates must contain the IP:{ip} Subject Alternative Name entry when these endpoints are part of the solution.
|
|
DNS:{breeze-fqdn}
|
Required
|
|
Authority Information Access
|
OCSP - URI:http://{ocsp-server}{:ocsp-port}{/ocsp-path}
|
Optional
|
|
CRL Distribution Points
|
URI:http://{crl-server}{:crl-port}{/crl-path} URLs and DNs used to identify the location of CRLs in LDAP directories may be quite complex; entities configuring or consuming these must be able to handle characters as defined by the LDAP URI specification in RFC 4516.
|
Optional
|
|
URI:ldap://{crl-server}{:crl-port}{/crl-dn}
|
Optional
|