![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 612](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697612.webp)
CRL Extension Reference
612
Netscape Certificate Management System Administrator’s Guide • June 2003
IssuingDistributionPoint
The
IssuingDistributionPoint
rule enables you to configure a Certificate
Manager to set the Issuing Distribution Point Extension in CRLs. The CRL issuing
point extension enables you to specify a pointer to a particular CRL and to include
additional information about the CRL at that location—whether it covers
revocation of end-entity certificates only, CA certificates only, or revoked
certificates that have a limited set of reason codes.
Optionally, each issuing point may contain a set of reason flags, indicating what
revocation reasons are covered by the CRL at the specified location. Note that you
can modify the rule to support any name form by making the appropriate changes
to the sample code provided for this purpose, see the CMS SDK.
For general guidelines on setting the issuing distribution point extension in CRLs,
see “issuingDistributionPoint” on page 773.
• If the type is
URL
, the value must be a non-relative universal
resource identifier (URI). For example:
http://testCA.example.com
.
• If the type is
iPAddress
, the value must be a valid IP address
specified in dot-separated numeric component notation. It can be the
IP address or the IP address including the netmask.
• If the type is
OID
, the value must be a unique, valid OID specified in
the dot-separated numeric component notation. Although you can
invent your own OIDs for the purposes of evaluating and testing this
server, in a production environment, you should comply with the
ISO rules for defining OIDs and for registering subtrees of IDs. See
Appendix H, “Object Identifiers” for information on allocating
private OIDs. For example,
1.2.3.4.55.6.5.99
.
• If the type is
otherName
, the name must be must be the absolute
path to the file that contains the general name in its base-64 encoded
format. For example,
/usr/netscape/servers/extn/ian/othername.txt
.
Table 14-8
IssuerAlternativeName Configuration Parameters (Continued)
Parameter
Description
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...