- Home
- All questions
- Question 246
CISSP study material · question 246 of 500
A certificate sets encipherOnly but leaves keyAgreement unset. How should a relying party interpret the encipherOnly bit?
Show the answer
Answer: B. Its meaning is undefined in the absence of keyAgreement.
RFC 5280 states the meaning of encipherOnly, like decipherOnly, is undefined without the keyAgreement bit; together they narrow the key to one direction during key agreement.
Source: RFC 5280 (IETF) — RFC 5280 > 4.2.1.3 Key Usage