KeyUsageExt Plug-in Module
196
Netscape Certificate Management System Plug-Ins Guide • May 2002
Figure 4-15
Key usage bit-specific variables in the SSL server certificate enrollment form
ClientCertKeyUsageExt Rule
The policy rule named
ClientCertKeyUsageExt
is an instance of the
KeyUsageExt
module. This rule is for setting the appropriate key-usage bits in SSL client
certificates. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression (
HTTP_PARAMS.certType==client
) ensures that the
rule is applied only to SSL client certificate requests.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The server is configured to set
digitalSignature
,
nonRepudiation
, and
keyEncipherment
key-usage bits in SSL client certificates.
Notice that the key-usage bits specified in the default policy rule match the bits
specified in the enrollment form for requesting SSL client certificates. Figure 4-16
shows the default directory-based enrollment form for end users with the
information related to the key usage extension variables highlighted—it shows
three of the total number of variables listed in Table 4-14 on page 187. Note that by
default three key-usage bits—
digitalSignature
,
nonRepudiation
, and
keyEncipherment
—are enabled and the remaining bits are disabled.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...