Windows Server 2003 Security Infrastructures

These tables list and explain the different fields that make up an X.509 certificate and CRL. More detailed information can be found in the ITU-TX.509 Recommendation (version 03/2000), which can be downloaded from the ITU Web site at www.itu.int.
| X.509 Field Name | Field Meaning | X.509 Version/Optional-Required/Criticality for Extensions |
|---|---|---|
| Version | X.509 version of the encoded certificate | V1 Required |
| SerialNumber | Unique serial number of the certificate. The serial number together with the issuer name identify a unique certificate. | V1 Required |
| Signature | Contains the algorithm identifier for the algorithm and hash function used by the CA when signing the certificate. | V1 Required |
| Issuer | Identifies the entity that has signed and issued the certificate. | V1 Required |
| Validity | Start and end date of the certificate or the time interval during which the CA warrants that it will maintain status information of the | V1 Required |
| Subject | Identifies the entity associated with the public key found in the subject public key field. | V1 Required |
| SubjectPublicKeyInfo | Carries public key being certified and identifies the algorithm of which the public key is an instance. | V1 Required |
| IssuerUniqueIdentifer | Used to uniquely identify an issuer in case of a name reuse. | V2 Optional |
| SubjectUniqueIdentifier | Used to uniquely identify a subject in case of a name reuse. | V2 Optional |
| Extensions | Allows addition of new fields to the certificate structure. | V3 Optional |
| AuthorityKeyIdentifier | Identifies public key to be used for certificate signature verification. | V3 Optional always Noncritical |
| SubjectKeyIdentifier | Identifies public key being certified . | V3 Optional always Noncritical |
| KeyUsage |