Extension-Specific Policy Module Reference
556
Netscape Certificate Management System Administrator’s Guide • February 2003
PrivateKeyUsagePeriodExt
The
PrivateKeyUsagePeriodExt
plug-in module enables you to add the Private
Key Usage Period Extension to certificates. The extension allows the certificate issuer
to specify a different validity period for the private key than the one specified for
the corresponding certificate. The extension is intended for use with digital
signature keys.
For general information about this extension, see “privateKeyUsagePeriod” on
page 732.
policyMap<n>.
issuerDomainPolicy
Specifies the OID assigned to the policy statement
<n>
of the issuing CA that
you want to map with the policy statement of another CA.
Permissible values: Any valid OID specified in dot-separated numeric
component notation (see the example). The OID that you specify should be in
the registered subtree of IDs reserved for your company’s use. Although you
can invent your own OIDs for the purposes of evaluating and testing this
server, in a production environment, you should comply with the ISO rules for
defining OIDs and for registering subtrees of IDs. See Appendix H, “Object
Identifiers
”
for information on allocating private OIDs.
Example:
1.2.3.4.5
policyMap<n>.
subjectDomainPolicy
Specifies the OID assigned to the policy statement
<n>
of the subject CA that
corresponds to the policy statement of the issuing CA.
Permissible values: Any valid OID specified in dot-separated numeric
component notation (see the example).
Example:
6.7.8.9.10
Table 11-37
PrivateKeyUsagePeriodExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules,” on page 485.
critical
Select to mark critical, deselect to mark noncritical (default).
Table 11-36
PolicyMappingsExt Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...