![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 496](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697496.webp)
Constraints-Specific Policy Module Reference
496
Netscape Certificate Management System Administrator’s Guide • June 2003
DSAKeyConstraints
The
DSAKeyConstraints
plug-in module imposes constraints on the following:
•
The minimum and maximum sizes for keys
•
The sizes of exponents
The policy restricts the key size to one of the sizes, such as 512 or 1024, supported
by CMS.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify public keys up to 512 bits in
length for end users and 1024 for servers, you can configure CMS to do so using the
policy.
During installation, CMS automatically creates an instance of the DSA key
constraints policy, named
DSAKeyRule
, that is enabled by default.
Table 11-4 describes the configuration parameters of the
DSAKeyConstraints
policy.
ldap.ldapconn.
maxConns
Specifies the maximum number of connections permitted to the LDAP directory;
when needed, connection pool can grow to this many (multiplexed) connections.
Permissible values:
3
to
10
; the default value is
5
.
attribute
Specifies the LDAP attribute, the presence of which is to be checked in the
certificate-enrollment request. Permissible values: Valid directory attributes,
separated by commas; the default value is
pin
.
value
If this parameter is non-empty, the attribute value must match this value for the
request to proceed to the next stage.
Table 11-4
DSAKeyConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 483.
Table 11-3
AttributePresentConstraints Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...