Study. uk . com
  1. Home
  2. All questions
  3. Question 248

CISSP study material · question 248 of 500

A certificate authority includes a path length constraint on an end entity certificate that has no CA boolean set. Which two statements from RFC 5280 apply? Choose two.

  1. A certificate authority must not include the field unless the CA boolean is asserted and keyCertSign is set.
  2. Where no path length constraint appears, no limit on path depth is imposed.
  3. Where no path length constraint appears, a default depth of one applies.
  4. The field is meaningful on end entity certificates and limits their reuse.
Show the answer

Answer: A. A certificate authority must not include the field unless the CA boolean is asserted and keyCertSign is set.
B. Where no path length constraint appears, no limit on path depth is imposed.

The field means something only where the CA boolean and certificate signing are both set, must be omitted otherwise, and its absence imposes no depth limit.

Source: RFC 5280 (IETF) — RFC 5280 > 4.2.1.9 Basic Constraints

Challenge yourself on this topic → Study as cards