UniqueSubjectNameConstraints Plug-in Module
Chapter
3
Constraints Policy Plug-in Modules
119
enablePreAgent
ApprovalChecki
ng
Specifies whether the request must be checked for the subject name uniqueness on
submission by the user, before the request gets queued for agent approval.
• Check the box if you want the server to check the certificate request for the subject
name uniqueness as soon as the user submits it.
• Uncheck the box if you want the server to check the certificate request for the
subject name uniqueness after agent approval; that is, you want the policy to be
applied to the request after an agent approves the request. You should choose this
option if you want the server to check the Key Usage extension (see
“KeyUsageExt Plug-in Module” on page 186) before determining whether to issue
the certificate.
enableKeyUsage
ExtensionCheck
ing
Specifies whether the certificate request must be checked for the Key Usage extension.
Note that the policy can check the certificate request for the Key Usage extension only
if you uncheck (disable) the
enablePreAgentApprovalChecking
parameter. The
reason for this is that, extensions are set on the request after agent approval, so this
checking can be done after an agent approves the request.
• Check the box if you want the server to check the certificate request for the Key
Usage extension. If you check the box, the server checks its internal database for
certificates that have the same subject name as the one specified in the request. For
each certificate that has the matching subject name, the server compares the Key
Usage extension of the certificate to the one specified in the request. If the server
finds a certificate that has the same subject name and Key Usage extension, it
rejects request. Otherwise, the server approves the request. (This choice is suitable
if you want to have multiple certificates with same subject names but for different
purposes, such as signing and encrypting. If key-usage comparison is to be done,
be sure to specify that this policy is to be applied after the Key Usage extension
policy; see section “Step 5. Reorder Policy Rules” in Chapter 18, “Setting Up
Policies” of CMS Installation and Setup Guide.)
• Uncheck the box if you don’t want the server to check the certificate request for
the Key Usage extension. If you uncheck the box, the server does not compare the
Key Usage extension in the request with the ones set in the existing certificates
that have the same subject name; it simply rejects requests with same subject
names.
Table 3-12
Description of parameters defined in the UniqueSubjectNameConstraints module (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...