Constraints-Specific Policy Module Reference
508
Netscape Certificate Management System Administrator’s Guide • February 2003
ValidityConstraints
The
ValidityConstraints
plug-in module enforces minimum and maximum
validity periods for certificates and changes them if the policy is not met.
Specifically, the policy imposes constraints on the following:
•
The duration of a certificate’s validity period (based on supported minimum
and maximum validity periods).
•
The lead and lag time for the beginning date and time (the
notBefore
and
notAfter
attributes in certificate requests) for the validity period; how far back
into the front or back the
notBefore
date could go in minutes.
If this policy rule is enabled, the server applies the rule to the certificate request
being processed, and then determines if the validity period in the request is
acceptable. The rule checks two X.509 attributes of the certificate, the
notBefore
and
notAfter
time, which together indicate the total validity life of a certificate, to
make sure that they conform to the configured ranges.
The rule checks that the value of the
notBefore
attribute in the request is not more
than
leadTime
minutes in the future; the
leadTime
is a configurable parameter in
the plug-in implementation. The ability to configure the value of the
leadTime
parameter in the policy rule allows you to prohibit end entities from requesting
certificates whose validity starts too far in the future, and yet allows some amount
of toleration of clock-skew problems. For example, if the current date and time is
01/15/2000
(
mm/dd/YYYY
) and
1:30 p.m
., the value of the
notBefore
attribute is
set to
3:00 p.m
., and that the
leadTime
is
10
minutes, then the request would fail,
because the validity requested begins more than 10 minutes in the future.
The rule also checks that the value of the
notBefore
attribute in the request is not
more than
lagTime
minutes in the past. For example, if the current date and time is
01/15/2000
(
mm/dd/yyyy
) and
1:30 p.m
., the value of the
notBefore
attribute is
set to 1:15 p.m., and the
lagTime
is set to
10
minutes, the request would fail
because the user has requested a certificate
15
minutes in the past. Note that a
request with
notBefore
set to
1:25
p.m. would have passed, however.
You may apply this policy to end-entity certificate enrollment requests.
NOTE
:KHQDSSO\LQJWKHYDOLGLW\FRQVWUDLQWVSROLF\WKHVHUYHUGRHVQRWFKHFNWKH
ODJWLPHLQDOOFHUWLILFDWHUHTXHVWV,WFKHFNVWKHODJWLPHRQO\LQWKRVHUHTXHVWV
WKDWDUHEDVHGRQWKH&50)SURWRFRO³FXUUHQWO\&50)LVWKHRQO\
HQUROOPHQWIRUPDWWKDWDOORZVDQHQGHQWLW\WRUHTXHVWDVSHFLILFYDOLGLW\
SHULRGZLWKWKH
notBefore
DWWULEXWHVHWWRDWLPHLQWKHSDVW
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...