Sun Java System Portal Server Secure Remote Access 7.2 Administration Guide

Certificate Trust Attributes

The trust attributes of a certificate indicate the following information:

The three available trust categories for each certificate are expressed in this order: “SSL, email, object signing”. Only the first category is useful for the Gateway. In each category position, zero or more trust attribute codes are used.

The attribute codes for the categories are separated by commas, and the entire set of attributes is enclosed by quotation marks. For example, the self-signed certificate generated and installed during the Gateway installation is marked "u,u,u" which means the certificate is a server certificate (user certificate) and not a root CA certificate.

Certificate Trust Attributes lists the possible attribute values and the meaning of each value.

Table 10–2 Certificate Trust Attributes

Attribute  

Description  

Valid peer 

Trusted peer (implies p) 

Valid CA 

Trusted CA to issue client certificates (implies c) 

Trusted CA to issue server certificates (SSL only) (implies c) 

Certificate can be used for authentication or signing 

Send warning (use with other attributes to include a warning when the certificate is used in that context)