CertificateRenewalWindowExt Plug-in Module
Chapter
4
Certificate Extension Plug-in Modules
155
Figure 4-6
Parameters defined in the CertificateRenewalWindowExt module
The configuration shown in Figure 4-6 creates a policy rule named
CertRenewWindowExtForClientCert
, which enforces a rule that the server should
set the certificate renewal window extension in client certificates only; the renewal
window starts 30 days before a certificate expires and ends with certificate
expiration.
Table 4-6 gives details about each of these parameters.
Table 4-6
Description of parameters defined in the CertificateRenewalWindowExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled.
• Check the box to enable the rule (default). If you enable the rule and set the
remaining parameters correctly, the server adds the certificate renewal
window extension to certificates specified by the
predicate
parameter.
• Uncheck the box to disable the rule. If you disable the rule, the server does not
add the extension to certificates; it ignores the values in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see section “Using Predicates in Policy Rules” in Chapter 18, “Setting
Up Policies” of CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==client
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...