AttributePresentConstraints Plug-in Module
86
Netscape Certificate Management System Plug-Ins Guide • March 2002
AttributePresentConstraints Plug-in Module
The
AttributePresentConstraints
plug-in module implements the attribute
present constraints policy. The module enables you to configure the Certificate
Manager and Registration Manager to reject a request if an LDAP attribute (for
example,
pin
) is not present in the enrolling user’s directory entry or if the attribute
does not have a specified value. An example usage is in “Step 3. Enable the
AttributePresentConstraints Policy” in Chapter 15, “Setting Up End-User
Authentication” of CMS Installation and Setup Guide.
Note that many of the parameters defined in the module (see Table 3-2 on page 88)
are specified in the same way as the modules provided for authenticating users
during directory-based enrollment.
RenewalValidityConstraints
Enforces the number of days before which a currently active
certificate can be renewed and sets a new validity period for the
renewed certificate. For details, see “RenewalValidityConstraints
Plug-in Module” on page 102.
RevocationConstraints
Allows or rejects requests for revocation of expired certificates. For
details, see “RevocationConstraints Plug-in Module” on page 106.
RSAKeyConstraints
Certifies only those RSA keys that have specific key lengths. For
details, see “RSAKeyConstraints Plug-in Module” on page 108.
SigningAlgorithmConstraints
Specifies the signature algorithm to be used by the CA (a
Certificate Manager) to sign certificates. For details, see
“SigningAlgorithmConstraints Plug-in Module” on page 111.
SubCANameConstraints
Checks for issuer name uniqueness and prevents a CA from
issuing a subordinate CA certificate with issuer name same as its
own. For details, see “SubCANameConstraints Plug-in Module”
on page 114.
UniqueSubjectNameConstraints
Checks for certificate subject name uniqueness and prevents
issuance of multiple certificates with same subject names. For
details, see “UniqueSubjectNameConstraints Plug-in Module” on
page 117.
ValidityConstraints
Checks whether the validity period of a certificate falls within a
specific validity period. For details, see “ValidityConstraints
Plug-in Module” on page 120.
Table 3-1
Default constraints-specific policy plug-in modules (Continued)
Plug-in module name
Function
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...