![Netscape Certificate Management System 6.0 Manual Download Page 228](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-0/certificate-management-system-6-0_manual_1674687228.webp)
PrivateKeyUsagePeriodExt Plug-in Module
228
Netscape Certificate Management System Plug-Ins Guide • March 2002
PolicyMappingsExt Rule
The rule named
PolicyMappingsExt
is an instance of the
PolicyMappingsExt
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression is set (
predicate=HTTP_PARAMS.certType==ca
) so
that the extension gets added to CA certificates only.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The number of policy mappings is set to 1 (
numPolicyMappings=1
) indicating
that a pair of policies are to be mapped.
•
The fields for entering the OIDs for policies that are to be mapped are left blank
for you to enter the appropriate values.
For details on individual parameters defined in the rule, see Table 4-23 on
page 226. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section “Step 2. Modify Existing Policy Rules” in
Chapter 18, “Setting Up Policies” of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section “Step 4. Add New Policy
Rules” in the same chapter.
PrivateKeyUsagePeriodExt Plug-in Module
The
PrivateKeyUsagePeriodExt
plug-in module implements the private key
usage period extension policy. This policy enables you to configure Certificate
Management System to add the Private Key Usage Period Extension defined in X.509
and PKIX standard RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) to
certificates. The extension allows the certificate issuer to specify a different validity
period for the private key than the one specified for the corresponding certificate.
The extension is intended for use with digital signature keys.
The PKIX standard recommends against the use of this extension. The standard
also recommends that CAs conforming to the standard must not generate
certificates with private key usage period extensions that are marked critical. For
general guidelines on setting this extension in certificates, see
“privateKeyUsagePeriod” on page 353.
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...