Constraints-Specific Policy Module Reference
498
Netscape Certificate Management System Administrator’s Guide • June 2003
KeyAlgorithmConstraints
The
KeyAlgorithmConstraints
plug-in module restricts the key algorithm
requested in certificates to the algorithms, such as RSA and DSA, supported by
CMS. In other words, this policy allows you to set restrictions on the types of
public keys certified by CMS.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify only those public keys that
comply with the PKCS-1 RSA Encryption Standard, you can configure the server
for that using the policy.
During installation, CMS automatically creates an instance of the key algorithm
constraints policy, named
KeyAlgRule
, that is enabled by default.
Table 11-6 describes the configuration parameters of the
KeyAlgorithmConstraints
policy.
Table 11-5
IssuerConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 483.
issuerDN
Specifies the name of the CA that has issued certificates that are to be checked. You
should enter the issuer name as it appears in the CA’s signing certificate; the same
name also appears as the issuer name in certificates the CA signs.
Example:
CN=bulkGenCA,OU=Information Systems,O=Example
Corporation,C=US
Table 11-6
KeyAlgorithmConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 483.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...