DSAKeyConstraints Plug-in Module
Chapter
3
Constraints Policy Plug-in Modules
91
DSAKeyConstraints Plug-in Module
The
DSAKeyConstraints
plug-in module implements the DSA key constraints
policy. This policy imposes constraints on the following:
•
The minimum and maximum sizes for keys
•
The sizes of exponents
The policy restricts the key size to one of the sizes, such as 512 or 1024, supported
by Certificate Management System.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify public keys up to 512 bits in
length for end users and 1024 for servers, you can configure Certificate
Management System to do so using the policy.
During installation, Certificate Management System automatically creates an
instance of the DSA key constraints policy. See “DSAKeyRule Rule” on page 94.
ldap.ldapconn.
maxConns
Specifies the maximum number of connections permitted to the LDAP directory;
when needed, connection pool can grow to this many (multiplexed) connections.
Permissible values:
3
to
10
; the default value is
5
.
Example:
9
attribute
Specifies the LDAP attribute, the presence of which is to be checked in the
certificate-enrollment request.
Permissible values: Valid directory attributes, separated by commas; the default
value is
pin
.
Example:
pin
value
If this parameter is non-empty, the attribute value must match this value for the
request to proceed to the next stage.
Table 3-2
Description of parameters defined in the AttributePresentConstraints module (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.0
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...