10.2 X.509 certificates
Because digital certificates are exchanged and automatically interpreted by various entities and systems, there must be a standard prescribing the format and data fields of a digital certificate. The oldest and most important digital certificate standard is called X.509, with v3 being its newest version.
In X.509, digital certificates are always issued by a CA. X.509 is an offspring of X.500, an early attempt by the OSI at a global directory structure, in which every entity has a globally unique Distinguished Name (DN). A distinguished name, in turn, is a collection of Relative Distinguished Names (RDNs). This naming scheme was also adopted for X.509 certificates. For example, according to his X.509 certificate, one of the authors of this book has the distinguished name C = DE, O = Hochschule der Medien, CN = Roland
Schmitz
, where C
stands for Country, DE
stands for Germany, O
stands for Organization, and CN
stands for Common Name. The CN should be unique within...