Configuring the Certificate Manager
120
Netscape Certificate Management System Administrator’s Guide • June 2003
Changing the Certificate Issuance Rules
You can change some of the rules about certificate issuance that were either
determined during installation, or are the system defaults. These include:
•
Whether certificates can be issued that are for validity periods longer than the
Certificate Managers CA signing certificate, the default is to not allow.
•
The serial number range the CA is able to use to issue certificates.
•
The signing algorithm used to sign certificates.
To change the certificate issuance rules:
1.
In the CMS window, select the Configuration tab.
2.
In the navigation tree, select Certificate Manager.
The General Setting tab appears.
3.
Change the following fields in this tab:
Override validity nesting requirement.
Specifies if the Certificate Manager
can issue certificates with validity periods beyond that of its CA signing
certificate.
If deselected and the Certificate Manager (CA) receives a request with validity
period extending beyond that of its CA signing certificate, it automatically
truncates the validity period to end on the day the CA signing certificate
expires.
Validity periods of certificates during enrollment is determined by the
ValidityConstraints
plug-in module, “ValidityConstraints,” on page 506.
Similarly, validity periods of certificates during renewal is determined by the
RenewalValidityConstraints
plug-in module, see
“RenewalValidityConstraints,” on page 499.
Certificate Serial Number.
Specifies the serial number range for certificates
issued by this Certificate Manager. The server assigns the serial number you
enter in the “Next serial number” to the next certificate it issues and the
number you enter in the “Ending serial number” to the last certificate it issues.
The serial number range enables you to deploy multiple CAs, balancing the
number of certificates each CA issues. Note that the combination of an issuer
name and a serial number uniquely identifies a certificate. To ensure that two
distinct certificates issued by the same authority doesn’t contain the same serial
number, make sure the serial number range does not overlap among cloned
CAs.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...