![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 501](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697501.webp)
Constraints-Specific Policy Module Reference
Chapter
11
Policies
501
RSAKeyConstraints
The
RSAKeyConstraints
plug-in module imposes constraints on the following:
•
The minimum and maximum sizes for keys
•
The exponent sizes
The policy restricts the key size to one of the sizes supported by CMS—512, 1024,
2048, or 4096. In other words, the policy allows you to set up restrictions on the
lengths of public keys certified by CMS.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify public keys up to 1024 bits in
length for end users, you can configure the server accordingly using the policy.
During installation, CMS automatically creates an instance of the RSA key
constraints polic, named
RSAKeyRule
, that is disabled by default.
Table 11-10 describes the configuration parameters of the
RSAKeyConstraints
policy.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see “Using Predicates in Policy Rules” on page 483.
allowExpiredCerts
Specifies whether to allow or prevent revocation of expired certificates. Select if
you want the server to revoke expired certificates (default). Deselect if you don’t
want the server to revoke expired certificates.
Table 11-10
RSAKeyConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable the rule (default).
Deselect to disable the rule.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 483.
Table 11-9
RevocationConstraints Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...