Skip to main content

4. Certificate and Certificate Extensions Profile

This section provides a profile for public key certificates to facilitate interoperability. The profile is based on the X.509 v3 certificate format and standard certificate extensions.

Main Topics

Key Concepts

Certificate Structure

The X.509 v3 certificate consists of three main components:

  • tbsCertificate (to-be-signed certificate)
  • signatureAlgorithm
  • signatureValue

Interoperability Goals

This profile aims to establish a common baseline for general applications requiring broad interoperability, with focus on:

  • Internet email
  • IPsec
  • WWW applications