2.23.1 Syntax Option 1

Note An alternative scenario for template schema version 4 is defined in section 2.23.2.

If either of the following is true:

  • The template version is 1 or 2.

  • The template version is 4 and the template has the CT_FLAG_USE_LEGACY_PROVIDER bit of the msPKI-Private-Key-Flag attribute set.

Then the msPKI-RA-Application-Policies attribute contains multistring attributes that specify a set of application policy OIDs for the RA certificates. Application policy OIDs are the same as extended key usage OIDs, as specified in [RFC3280] section 4.2.1.13.