OCSPNoCheckExt Plug-in Module
220
Netscape Certificate Management System Plug-Ins Guide • March 2002
OCSPNoCheckExt Rule
The policy rule named
OCSPNoCheckExt
is an instance of the
OCSPNoCheckExt
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression is set
(
predicate=HTTP_PARAMS.certType==ocspResponder
) so that the extension
gets added to OCSP responder certificates only.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
For details on individual parameters defined in the rule, see Table 4-21 on
page 220. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section “Step 2. Modify Existing Policy Rules” in
Chapter 18, “Setting Up Policies” of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section “Step 4. Add New Policy
Rules” in the same chapter.
Table 4-21
Description of parameters defined in the OCSPNoCheckExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server adds
the OCSP no check extension to certificates specified by the
predicate
parameter.
• If you disable the rule, the server does not add the extension to certificates; it
ignores the values in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see section “Using Predicates in Policy Rules” in Chapter 18, “Setting Up Policies” of
CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==ocspResponder
critical
Specifies whether the extension should be marked critical or noncritical in certificates
specified by the
predicate
parameter. Check the box if you want the server to mark
the extension critical. Uncheck the box if you want the server to mark the extension
noncritical (default).
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...