KeyUsageExt Plug-in Module
190
Netscape Certificate Management System Plug-Ins Guide • May 2002
Table 4-15
Description of parameters defined in the KeyUsageExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule, the server checks the key usage extension bits specified
in the remaining fields, and adds the extension with those bits to certificates
specified by the
predicate
parameter.
• If you disable the rule, the server does not add the extension to certificates; it
ignores the key usage extension-specific bits specified in the policy
configuration and in the enrollment forms.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate
expression, see section “Using Predicates in Policy Rules” in Chapter 18, “Setting
Up Policies” of CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==client
critical
Specifies whether the extension should be marked critical or noncritical in
certificates specified by the
predicate
parameter. Check the box if you want the
server to mark the extension critical (default). Uncheck the box if you want the
server to mark the extension noncritical.
digitalSignature
Specifies whether to set the
digitalSignature
bit (or bit 0) of the key usage
extension in certificates specified by the
predicate
parameter.
Permissible values:
true
,
false
, or
HTTP_INPUT
.
• Select
true
if you want the server to set the bit (default).
• Select
false
if you don’t want the server to set the bit.
• Select
HTTP_INPUT
if you want the server to check the certificate request for
the HTTP input variable corresponding to the
digitalSignature
bit and set
the bit accordingly. If the variable is set to
true
, the server sets the bit. If the
variable doesn’t exist or if it is set to
false
(or any other value), the server
doesn’t set the bit.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...