BasicConstraintsExt Plug-in Module
146
Netscape Certificate Management System Plug-Ins Guide • May 2002
The configuration shown in Figure 4-4 creates a policy rule named
BasicConsExtForCACert
, which enforces a rule that the server should set the basic
constraints extension in all CA certificates.
Table 4-4 gives details about each of these parameters.
Table 4-4
Description of parameters defined in the BasicConstraintsExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server adds
the basic constraints extension to certificates specified by the
predicate
parameter.
• If you disable the rule, the server does not add the extension to certificates; it
ignores the values in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see section “Using Predicates in Policy Rules” in Chapter 18, “Setting Up Policies” of
CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==ca
critical
Specifies whether the extension should be marked critical or noncritical in certificates
specified by the
predicate
parameter. Check the box if you want the server to mark
the extension critical (default). Uncheck the box if you want the server to mark the
extension noncritical.
isCA
Specifies whether the certificate subject is a CA. If you select the option, the server
checks the
maxPathLen
parameter and sets the specified path length in the
certificate. If you deselect the option, the server treats the certificate subject as a
non-CA and ignores the value specified for the
maxPathLen
parameter.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...