Extension-Specific Policy Module Reference
518
Netscape Certificate Management System Administrator’s Guide • February 2003
Because the renewal process requires end users to remember when their certificates
expire and renew them before the expiry date, some clients provide built-in
support for automated renewal. Inclusion of the certificate renewal window
extension in certificates is useful in a PKI setup with such clients.
Unlike some of the other policy modules, CMS does not create an instance of the
certificate renewal window extension policy during installation. If you want the
server to add this extension to certificates, you must create an instance of the
CertificateRenewalWindowExt
module and configure it.
Table 11-19
CertificateRenewalWindowExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see “Using Predicates in Policy Rules” on page 485.
critical
Specifies whether the extension should be marked critical or noncritical. Select to
mark critical, deselect to mark noncritical (default).
relativeBeginTime
Specifies the first time automatic renewal of certificate that contains the extension
should be attempted.
Permissible values:
0
or
n
.
•
0
specifies that the renewal window begins at the same time the certificate is
issued; the
beginTime
field of the extension will be set to the time of
certificate issuance.
•
n
specifies a future time for certificate renewal; the
beginTime
field of the
extension will be set to the specified time since certificate issuance. You can
specify the time period in seconds, minutes, hours, days, or months. Use the
following suffixes to indicate the time unit.
s
- seconds
m
- minutes
h
- hours
D
- days
M
- months
For example, if you’re issuing certificates with a validity period of two years
and want the renewal window to begin a month before the certificates expire,
and want to specify the interval in months, you would enter
23M
in this field.
To specify the same validity interval in seconds, you would set the value to
59616000s
(23 months x 30 days x 24 hours x 60 minutes x 60 seconds).
Example:
23M
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...