KeyUsageExt Plug-in Module
194
Netscape Certificate Management System Plug-Ins Guide • March 2002
•
The server is configured to set
digitalSignature
,
nonRepudiation
,
keyCertsign
, and
cRLSign
bits in CA signing certificates. Notice that the
key-usage bits specified in the default policy rule match the bits specified in the
enrollment form (
ManCAEnroll.html
) for requesting CA signing certificates
(see Figure 4-13).
Figure 4-13
Key usage bit-specific variables in the Certificate Manager enrollment form
RMCertKeyUsageExt Rule
The policy rule named
RMCertKeyUsageExt
is an instance of the
KeyUsageExt
module. This rule is for setting the appropriate key-usage bits in Registration
Managers’ signing certificates; see section “Signing Key Pair and Certificate” in
Chapter 14, “Managing CMS Keys and Certificates” of CMS Installation and Setup
Guide. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression (
HTTP_PARAMS.certType==ra
) ensures that the rule
is applied only to Registration Manager signing certificate requests.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...