Constraints-Specific Policy Module Reference
500
Netscape Certificate Management System Administrator’s Guide • June 2003
The renewal validity constraints policy enables you to enforce certain restrictions
on certificate-renewal requests, when end entities attempt to renew their
certificates.
During installation, CMS automatically creates an instance of the renewal validity
constraints policy, named
DefaultRenewalValidityRule
, that is enabled by
default.
Table 11-8 describes the configuration parameters of the
RenewalValidityConstraints
policy.
RevocationConstraints
The
RevocationConstraints
plug-in module imposes constraints on revocation
of expired certificates—it allows or restricts the server from revoking expired
certificates. You may apply this policy to end-entity certificate revocation requests.
During installation, CMS automatically creates an instance of the revocation
constraints policy, named
RevocationConstraintsRule
, that is enabled by
default.
Table 11-9 describes the configuration parameters of the
RevocationConstraints
policy.
Table 11-8
RenewalValidityConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect
to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate
expression, see “Using Predicates in Policy Rules” on page 483.
minValidity
Specifies the minimum validity period, in days, for renewed certificates.
maxValidity
Specifies the maximum validity period, in days, for renewed certificates.
renewalInterval
Specifies how many days before its expiration that a certificate can be renewed.
Table 11-9
RevocationConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default),
deselect to disable.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...