Extension-Specific Policy Module Reference
Chapter
11
Policies
549
NSCertTypeExt
The
NSCertTypeExt
plug-in module enables you to add the Netscape Certificate
Type extension to certificates. The extension identifies the certificate type—for
example, it identifies whether the certificate is a CA certificate, server SSL
certificate, client SSL certificate, object signing certificate, or S/MIME
certificate—and thus enables you to restrict the usage of a certificate to
predetermined purposes.
•
If the extension exists in a certificate, it limits the uses of the certificate to those
specified (it limits the applications for a certificate).
•
If the extension is not present, the certificate can be used for all applications
except object signing.
The Netscape certificate type extension is a string of boolean bit-flags, each bit
identifying the purpose for which a certificate to be used. Table 11-31 lists the bits
and their designated purposes. The extension has no default value.
displayText
Specifies the textual statement that should be included in certificates. If you want to
embed a textual statement (for example, your company’s legal notice) in certificates,
then add that statement here. The text you enter here will be displayed to a relying
party when the certificate is used or viewed.
Permissible values: A string with up to 200 characters.
Example:
Example Corporation’s CPS incorp. by reference liab.
ltd. (c) 2002 Example Corporation
commentfile
Specifies the path to the file that contains the textual statement that should be
included in certificates; be sure to include the complete path, including the filename.
Note that the existence of the file is not checked at the time of policy configuration.
The filename will be checked when the policy is applied to a request.
Example:
/usr/netscape/CApolicies/UserCertpolicy.txt
Table 11-31
Netscape certificate type extension bits and designated purposes
Bit
Purpose
Description
0
SSL Client
Specifies that the certificate can be used by clients for authentication
during SSL connections.
Table 11-30
NSCCommentExt Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...