Extension-Specific Policy Module Reference
Chapter
11
Policies
541
NameConstraintsExt
The
NameConstraintsExt
plug-in module enables you to add the Name Constraints
Extension to certificates. The extension is used in CA certificates to indicate a name
space within which subject names or subject alternative names in subsequent
certificates in a certification path or chain should be located.
For general information about this extension, see “nameConstraints” on page 730.
During installation, CMS automatically creates an instance of the name constraints
extension policy, named
NameConstraintsExt
, that is disabled by default.
decipherOnly
Specifies whether to set the
decipherOnly
bit (or bit 8) of the key usage extension
in certificates specified by the
predicate
parameter.
Permissible values:
true
,
false
, or
HTTP_INPUT
.
• Select
true
if you want the server to set the bit (default).
• Select
false
if you don’t want the server to set the bit.
• Select
HTTP_INPUT
if you want the server to check the certificate request for
the HTTP input variable corresponding to the
decipherOnly
bit and set the
bit accordingly. If the variable is set to
true
, the server sets the bit. If the
variable doesn’t exist or if it is set to
false
(or any other value), the server
doesn’t set the bit.
Table 11-29
NameConstraintsExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect
to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be
applied to all certificate requests, leave the field blank (default). To form a
predicate expression, see section “Using Predicates in Policy Rules” in
Chapter 18, “Setting Up Policies” of CMS Administrator’s Guide.
Example:
HTTP_PARAMS.certType==ca
critical
Specifies whether the extension should be marked critical or noncritical.
Select to mark critical (default), deselect to mark noncritical.
Table 11-28
KeyUsageExt Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...