CRLReason Rule
284
Netscape Certificate Management System Plug-Ins Guide • March 2002
CRLReason Rule
The
CRLReason
rule enables you to configure a Certificate Manager to set the CRL
ReasonCode Extension defined in X.509 and PKIX standard RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) in CRL entries. The extension is used
to identify the reason for the revocation of a certificate included in the CRL.
For general guidelines on setting the CRL reason code in CRL entries, see
“reasonCode” on page 366.
The revocation reasons defined by the standard are listed in Table 7-4.
Table 7-3
Description of parameters defined in the CRLNumber rule
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule.
Uncheck the box to disable the rule (default).
• If you enable the rule and set the remaining parameters correctly, the server sets
the CRL number extension in CRLs.
• If you disable the rule, the server does not add the extension to CRLs; it ignores
the values in the remaining fields.
critical
Specifies whether the extension should be marked critical or noncritical in CRLs
issued by the server. Check the box if you want the server to mark the extension
critical. Uncheck the box if you want the server to mark the extension noncritical
(default).
Table 7-4
Certificate revocation reasons
Code
Reason
0
unspecified
1
keyCompromise
2
cACompromise
3
affiliationChanged
4
superseded
5
cessationOfOperation
6
certificateHold
8
removeFromCRL
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...