AuthInfoAccessExt Plug-in Module
140
Netscape Certificate Management System Plug-Ins Guide • March 2002
AuthInfoAccessExt Rule
The rule named
AuthInfoAccessExt
is an instance of the
AuthInfoAccessExt
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
•
The rule is disabled.
•
The predicate expression (
predicate=HTTP_PARAMS.certType==client
)
ensures that the policy is to be applied to client certificate requests processed
by the server.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The total number of access locations to be contained or allowed in the
extension is set to 1 (
numADs=1
).
•
The access method for retrieving additional information about the CA that has
issued the certificate in which the extension appears is set to OCSP
(
ad0_method=ocsp
).
•
The general-name type for the location that contains additional information
about the CA that has issued the certificate in which the extension appears is
set to URL (
ad0_location_type=URL
).
•
The address or location to get additional information about the CA that has
issued the certificate in which this extension appears is left blank for you to
enter the URL at which the OCSP responder will service requests from
OCSP-compliant clients.
Note that if you installed the Certificate Manager with it’s built-in OCSP service
enabled, the policy rule will be enabled and the address location (
ad0_location=
)
will be pointed to the Certificate Manager’s nonSSL end-entity port. For example, if
the nonSSL end-entity port of your Certificate Manager is 80, the URL would look
like this:
http://ocspResponder.example.com:80/ocsp
For details on individual parameters defined in the rule, see Table 4-2 on page 135.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section “Step 2. Modify Existing Policy Rules” in Chapter 18,
“Setting Up Policies” of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section “Step 4. Add New Policy Rules” in the
same chapter.
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...