What is the difference between a critical and non-critical extension?
Originally Published: 2008-01-17
Article Number
Applies To
RSA Certificate Manager
Issue
Not sure if Critical or non-critical should be selected when issuing a certificate
Resolution
According to the X.509 standard, the user of a certificate should reject the certificate if an extension is flagged as critical and is not recognized. If the extension is flagged as non-critical and is aslo not recognized, the application may decide to accept the certificate anyway.
As an example, most browsers will recognize major extensions like KeyUsage, so it is a good practice to leave this extension as critical.
Related Articles
Critical Updates for RSA SecurID Access Components Used with the Cloud Authentication Service 9Number of Views Critical System Event Types 82Number of Views What web browsers have the RSA 2048 Root CA embedded in it? 11Number of Views Renaming an RSA Identity Governance & Lifecycle Notification Rule creates an orphan event in Scheduler 238Number of Views How to modify the low disk space critical event email warning threshold from 5 GB to 10 GB free in RSA Authentication Mana… 257Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update
Don't see what you're looking for?