KeyUsageExt Plug-in Module
Chapter
4
Certificate Extension Plug-in Modules
195
•
The server is configured to set
digitalSignature
and
nonRepudiation
bits
in Registration Manager signing certificates. Notice that the key-usage bits
specified in the default policy rule match the bits specified in the enrollment
form (
ManRAEnroll.html
) for requesting Registration Manager signing
certificates (see Figure 4-14).
Figure 4-14
Key usage bit-specific variables in the Registration Manager enrollment form
ServerCertKeyUsageExt Rule
The policy rule named
ServerCertKeyUsageExt
is an instance of the
KeyUsageExt
module. This rule is for setting the appropriate key-usage bits in SSL server
certificates. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression (
HTTP_PARAMS.certType==server
) ensures that the
rule is applied only to SSL server certificate requests.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The server is configured to set
digitalSignature
,
nonRepudiation
,
keyEncipherment
, and
dataEncipherment
bits in SSL server certificates.
Notice that the key-usage bits specified in the default policy rule match the bits
specified in the enrollment form (
ManServerEnroll.html
) for requesting SSL
server certificates (see Figure 4-15).
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...