BasicConstraintsExt Plug-in Module
144
Netscape Certificate Management System Plug-Ins Guide • May 2002
AuthorityKeyIdentifierExt Rule
The rule named
AuthorityKeyIdentifierExt
is an instance of the
AuthorityKeyIdentifierExt
module. Certificate Management System
automatically creates this rule during installation. By default, the rule is configured
as follows:
•
The rule is enabled.
•
The predicate expression is left blank so that the extension gets added to all
certificates the server issues.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The rule specifies that a SHA-1 hash of the CA’s subject public key info be used
if the CA certificate does not have a Subject Key Identifier extension
(
AltKeyIdType=SpkiSHA1
).
For details on individual parameters defined in the rule, see Table 4-3 on page 143.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section “Step 2. Modify Existing Policy Rules” in Chapter 18,
“Setting Up Policies” of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section “Step 4. Add New Policy Rules” in the
same chapter.
BasicConstraintsExt Plug-in Module
The
BasicConstraintsExt
plug-in module implements the basic constraints
extension policy. This policy enables you to configure Certificate Management
System to add the Basic Constraints Extension defined in X.509 and PKIX standard
RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) in certificates. The
extension identifies whether the Certificate Manager is a CA. In addition, the
extension is also used during the certificate chain verification process to identify
CA certificates and to apply certificate chain-path length constraints.
You should consider adding this extension to all CA certificates (root as well as
subordinate) issued by Certificate Management System. The current PKIX
standard requires that this extension be marked critical and that it appear in all CA
certificates. The standard also recommends that the extension should not appear in
end-entity certificates. For general guidelines on setting the basic constraints
extension, see “basicConstraints” on page 341.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...