IssuerConstraints Plug-in Module
96
Netscape Certificate Management System Plug-Ins Guide • May 2002
IssuerRule Rule
The rule named
IssuerRule
is an instance of the
IssuerConstraints
module.
Certificate Management System automatically creates this rule during installation.
By default, the rule is configured as follows:
•
The rule is disabled; for the rule to be effective, it must be enabled and
configured appropriately.
•
The predicate expression is set (
predicate=HTTP_PARAMS.certType==client
AND certauthEnroll==on
) so that the rule is applied to only those
client-certificate requests that have certificate-based authentication turned on.
•
The issuer DN field is left blank for you to enter the appropriate information.
Table 3-4
Description of parameters defined in the IssuerConstraints module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server
checks for certificates issued by the specified CA and enforces certificate-based
enrollment.
• If you disable the rule, the server does not check for certificates issued by a CA; it
ignores the values specified in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want the rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see
section “Using Predicates in Policy Rules” in Chapter 18, “Setting Up Policies” of
CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==client AND
HTTP_PARAMS.certauthEnroll==on
issuerDN
Specifies the name of the CA that has issued certificates that are to be checked. You
should enter the issuer name as it appears in the CA’s signing certificate; the same
name also appears as the issuer name in certificates the CA signs.
Permissible values: A valid issuer name.
Example:
CN=bulkGenCA,OU=Information Systems,O=Example
Corporation,C=US
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...