Extension-Specific Policy Module Reference
Chapter
11
Policies
509
Note that if you installed the Certificate Manager with it’s built-in OCSP service
enabled, the policy rule will be enabled and the address location (
ad0_location=
)
will be pointed to the Certificate Manager’s non-SSL end-entity port. For example,
if the non-SSL end-entity port of your Certificate Manager is 80, the URL would
look like this:
http://ocspResponder.example.com:80/ocsp
NOTE
The CMS configuration file (
CMS.cfg
) includes a parameter named
jss.ocspcheck.enable
, which enables you to specify whether a
CMS manager should use Online Certificate Status Protocol (OCSP)
to verify the revocation status of the certificate it receives as a part
of SSL client or server authentication (from clients or servers it
makes connections with). If you change the value of this parameter
to
true
, the CMS manager reads the Authority Information Access
extension in the certificate and verifies the revocation status of the
certificate from the OCSP responder specified in the extension.
Table 11-15
AuthInfoAccessExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 483.
critical
Specifies whether the extension should be marked critical or noncritical. Select to
mark critical, deselect to mark noncritical (default).
numADs
Specifies the total number of access locations to be contained or allowed in the
extension. The default is set to 3. You can set 0 specifying no locations can be
contained in the extension, or any integer <n>, number of fields.
Note that each location has its own set of configuration parameters and you must
specify appropriate values for each of those parameters; otherwise the policy rule will
return an error. Each set of configuration parameters is distinguished by
<n>
, which
is an integer derived from the value you assign in this field. For example, if you set
the
numADs
parameter to 2,
<n>
would be
0
and
1
.
ad<n>_method
Specifies the access method for retrieving additional information about the CA that
has issued the certificate in which the extension appears.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...