SubCANameConstraints Plug-in Module
114
Netscape Certificate Management System Plug-Ins Guide • March 2002
SigningAlgRule Rule
The rule named
SigningAlgRule
is an instance of the
SigningAlgorithmConstraints
module. Certificate Management System
automatically creates this rule during installation. By default, the rule is configured
as follows:
•
The rule is enabled.
•
The predicate expression is left blank so that the rule is applied to all certificate
enrollment and renewal requests processed by the server.
•
The signature algorithms allowed are MD5 with RSA, MD2 with RSA, and
SHA-1 with RSA (
algorithms=MD5withRSA,MD2withRSA,SHA1withRSA
).
For details on individual parameters defined in the rule, see Table 3-10 on
page 113. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section “Step 2. Modify Existing Policy Rules” in
Chapter 18, “Setting Up Policies” of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section “Step 4. Add New Policy
Rules” in the same chapter.
SubCANameConstraints Plug-in Module
The
SubCANameConstraints
plug-in module implements the subordinate CA
name constraints policy. This policy restricts a CA from issuing a subordinate CA
certificate that has the same issuer name as that of the CA itself—that is, the policy
prevents a situation where the signing certificates of a CA and its subordinate CA
have identical issuer names.
This policy must be turned on if you’re planning to issue subordinate CA
certificates. The reason for this is that, whenever the Certificate Manager issues a
certificate, it stores the related information in its internal database; see Chapter 12,
“Setting Up Internal Database” of CMS Installation and Setup Guide. If the CA
issues a subordinate CA certificate with an issuer DN that matches its own issuer
DN, the internal database will not function properly.
You may apply this policy to CA certificate enrollment and renewal requests.
During installation, Certificate Management System automatically creates an
instance of the subordinate CA name constraints policy. See
“SubCANameConstraints Rule” on page 116.
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...