RSAKeyConstraints Plug-in Module
108
Netscape Certificate Management System Plug-Ins Guide • May 2002
For details on individual parameters defined in the rule, see Table 3-8 on page 107.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section “Step 2. Modify Existing Policy Rules” in Chapter 18,
“Setting Up Policies” of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section “Step 4. Add New Policy Rules” in the
same chapter.
RSAKeyConstraints Plug-in Module
The
RSAKeyConstraints
plug-in module implements the RSA key constraints
policy. This policy imposes constraints on the following:
•
The minimum and maximum sizes for keys
•
The exponent sizes
The policy restricts the key size to one of the sizes supported by Certificate
Management System—512, 1024, 2048, or 4096. In other words, the policy allows
you to set up restrictions on the lengths of public keys certified by Certificate
Management System.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify public keys up to 1024 bits in
length for end users, you can configure the server accordingly using the policy.
During installation, Certificate Management System automatically creates an
instance of the RSA key constraints policy. See “RSAKeyRule Rule” on page 110.
Configuration Parameters of
RSAKeyConstraints
In the CMS configuration file, the
RSAKeyConstraints
module is identified as
<subsystem>.Policy.impl.RSAKeyConstraints.class=com.netscape.cms.
policy.RSAKeyConstraints
, where
<subsystem>
is
ca
or
ra
(prefix identifying
the subsystem).
In the CMS window, the module is identified as
RSAKeyConstraints
. Figure 3-9
shows how the configurable parameters for the module are displayed in the CMS
window.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...