IssuerAltNameExt Plug-in Module
Chapter
4
Certificate Extension Plug-in Modules
181
GenericASN1Ext Rule
The rule named
GenericASN1Ext
is an instance of the
GenericASN1Ext
module.
Certificate Management System automatically creates this rule during installation.
By default, the rule is configured as follows:
•
The rule is disabled; for the rule to be effective, it must be enabled and
configured appropriately.
•
The predicate field is left blank so that the extension gets added to all
certificates the server issues.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
Other fields are left blank for you to enter the appropriate information.
For details on individual parameters defined in the rule, see Table 4-11 on
page 177. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section “Step 2. Modify Existing Policy Rules” in
Chapter 18, “Setting Up Policies” of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section “Step 4. Add New Policy
Rules” in the same chapter.
IssuerAltNameExt Plug-in Module
The
IssuerAltNameExt
plug-in module implements the issuer alternative name
extension policy. This policy enables you to configure Certificate Management
System to add the Issuer Alternative Name Extension defined in X.509 and PKIX
standard RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) to certificates.
This extension enables binding of or associating Internet style identities—such as
Internet electronic mail address, a DNS name, an IP address, and a uniform
resource indicator (URI)— with the certificate issuer.
For general guidelines on setting the issuer alternative name extension, see
“issuerAltName” on page 347.
The issuer alternative name extension policy in Certificate Management System
allows setting of the issuer alternative name extension as defined in its X.509
definition. The policy enables you to associate the following alternative identities
to a CA, by including them in the extension:
•
An rfc822 name
•
A directory name
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...