- Home
- All questions
- Question 251
CISSP study material · question 251 of 500
A certificate authority's signing key will only ever sign certificates and revocation lists. Which practice does RFC 5280 recommend for its keyUsage bits?
Show the answer
Answer: B. Leave digitalSignature and nonRepudiation clear so the certificate claims no more than it does.
Where the key signs only certificates or revocation lists, those two bits should stay clear, though they may be set if other objects are signed too.
Source: RFC 5280 (IETF) — RFC 5280 > 4.2.1.3 Key Usage