Configuring Authentication for End-User Enrollment
540
Netscape Certificate Management System Installation and Setup Guide • October 2001
3.
In the Web Access section, check the “Enable end-entity interaction” option if
you want end entities to be able to interact with the selected Certificate
Manager via the HTTPS port; leave it unchecked to disable end-entity
interaction with the server.
Note that if you disable end-entity interaction, the Network tab still shows the
HTTPS port and allows you to configure it (see “Configuring Port Numbers”
on page 374). However, you should know that the server ignores this port.
4.
In the Certificate Validity section, check the “Override validity nesting
requirement” option, if you want the Certificate Manager to issue certificates
with validity periods beyond that of its CA signing certificate; see “CA Signing
Key Pair and Certificate” on page 437).
If you leave the box unchecked and if the Certificate Manager (CA) finds a
request with validity period extending beyond that of its CA signing
certificate, it automatically truncates the validity period to end on the day the
CA signing certificate expires. For example, if the CA signing certificate expires
on June 10, 2004, any enrollment or renewal request with validity period
beyond June 10, 2004 will have validity period truncated to end on June 10,
2004.
Validity periods of certificates during enrollment is determined by the policy
explained in
ValidityConstraints
plug-in module. Similarly, validity
periods of certificates during renewal is determined by the policy explained in
RenewalValidityConstraints
plug-in module. Both the modules are
explained in CMS Plug-ins Guide.
5.
In the Certificate Serial Number section, specify the serial number range for
certificates issued by this Certificate Manager. The server assigns the serial
number you enter in the “Next serial number” to the next certificate it issues
and the number you enter in the “Ending serial number” to the last certificate it
issues.
The serial number range enables you to deploy multiple CAs, balancing the
number of certificates each CA issues. Note that the combination of an issuer
name and a serial number uniquely identifies a certificate. To ensure that two
distinct certificates issued by the same authority doesn’t contain the same serial
number, make sure the serial number range does not overlap among cloned
CAs. (For information on cloning CAs, “Cloning a Certificate Manager” on
page 286.)
Also note that when a CA exhausts all its serial numbers, you can revive it by
changing the values in the “Next serial number” and “Ending serial number”
fields, followed by restarting the Certificate Manager.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...