nExtended
Key Usage
nBecause
Key Usage wasn’t confusing enough!
nPrivate
Key Usage Period
nCA
attempt to limit key validity period
nAlternative
names
nEverything
which doesn’t fit in a DN
nRFC822
names, DNS names, URIs
nIP
addresses, X.400 names, EDI, etc.