Extension-Specific Policy Module Reference
Chapter
11
Policies
547
NSCertTypeExt
The
NSCertTypeExt
plug-in module enables you to add the Netscape Certificate
Type extension to certificates. The extension identifies the certificate type—for
example, it identifies whether the certificate is a CA certificate, server SSL
certificate, client SSL certificate, object signing certificate, or S/MIME
certificate—and thus enables you to restrict the usage of a certificate to
predetermined purposes.
•
If the extension exists in a certificate, it limits the uses of the certificate to those
specified (it limits the applications for a certificate).
•
If the extension is not present, the certificate can be used for all applications
except object signing.
The Netscape certificate type extension is a string of boolean bit-flags, each bit
identifying the purpose for which a certificate to be used. Table 11-31 lists the bits
and their designated purposes. The extension has no default value.
displayText
Specifies the textual statement that should be included in certificates. If you want to
embed a textual statement (for example, your company’s legal notice) in certificates,
then add that statement here. The text you enter here will be displayed to a relying
party when the certificate is used or viewed.
Permissible values: A string with up to 200 characters.
Example:
Example Corporation’s CPS incorp. by reference liab.
ltd. (c) 2002 Example Corporation
commentfile
Specifies the path to the file that contains the textual statement that should be
included in certificates; be sure to include the complete path, including the filename.
Note that the existence of the file is not checked at the time of policy configuration.
The filename will be checked when the policy is applied to a request.
Example:
/usr/netscape/CApolicies/UserCertpolicy.txt
Table 11-31
Netscape certificate type extension bits and designated purposes
Bit
Purpose
Description
0
SSL Client
Specifies that the certificate can be used by clients for authentication
during SSL connections.
Table 11-30
NSCCommentExt Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...