83
Chapter
3
Constraints Policy Plug-in Modules
You can configure Netscape Certificate Management System (CMS) to apply
certain organizational policies to an end entity’s certificate enrollment, renewal,
and revocation requests before servicing them. For example, some of the policies
you might want Certificate Management System to apply to these requests may
include setting a minimum and maximum limit on validity period and key length
of certificates, setting extensions based on the end entity’s role within an
organization, setting signing algorithms, and so on.
Certificate Management System comes with various policy plug-in modules that
define the formulation of a certificate’s content and govern the server’s certificate
generation and management operations. The modules are categorized, based on
their functionality, into two groups: constraints-specific policy modules and
extension-specific policy modules.
This chapter explains the constraints-specific policy plug-in modules in detail—it
lists and briefly describes the modules that are installed with Certificate
Management System, and then explains each one in detail. For details on
extension-specific modules, see Chapter 4, “Certificate Extension Plug-in
Modules”.
The chapter has the following sections:
•
Overview of Constraints-Specific Policy Modules (page 84)
•
AttributePresentConstraints Plug-in Module (page 86)
•
DSAKeyConstraints Plug-in Module (page 91)
•
IssuerConstraints Plug-in Module (page 94)
•
KeyAlgorithmConstraints Plug-in Module (page 97)
•
RenewalConstraints Plug-in Module (page 99)
•
RenewalValidityConstraints Plug-in Module (page 102)
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...