| Description | Use of the AuthorityKeyIdentifier extension in Certificate Revocation Lists === The description of the Application Instance Certificate in Part 6 (1.04) Section 6.2.2 lists the AuthorityKeyIdentifier as a mandatory element of CA signed certificates.
This identifier helps to find the issuer certificate of a signed certificate when the issuer name is not unique.
The same problem arises when Certificate Revocation Lists are used, which, in their standard form, only include the issuer name.
RFC https://tools.ietf.org/html/rfc5280#section-5.2.1 lists the AuthorityKeyIdentifier extension for Certificate Revocation Lists.
Please consider adding a section about this CRL extension. |
|---|