Introduction to Policy
586
Netscape Certificate Management System Installation and Setup Guide • October 2001
You can define your own attributes for predicates, if there’s a need. For example,
assume you have two organizational units Sales and Manufacturing and you want
to issue client certificates with different validity periods to users in these two units.
A quick and easy way to accomplish this would be to define a new attribute for the
organizational unit, add the attribute to the enrollment form that the users in these
organizational units use for certificate enrollment (so that the server receives it
from the HTTP input), and use the attribute in the predicate expression for the
validity constraints policy—a policy rule that determines the validity period of
certificates the server issues. For details on this policy, check the
“ValidityConstraints Plug-in Module” section in Chapter 3, “Constraints Policy
Plug-in Modules” of CMS Plug-ins Guide.
Enrollment
cepsubstore
Specifies the name of the CEP service; for example,
cep1
and
cep2
. When setting up multiple CEP services, you can use
predicates to differentiate one service for another; see “Step 4.
Set Up Multiple CEP Services” on page 820.
Enrollment,
Renewal, and
Revocation
requestStatus
Specifies when (or the phase in which) a request gets
subjected to policy processing:
•
begin
specifies that the request be subjected to a policy
before it gets queued for agent approval.
•
pending
specifies that the request be subjected to a
policy after agent approval.
Renewal
requestFormat
Specifies the certificate request format. Default values
include the following:
•
clientAuth
•
pkcs10
Default attributes from an authentication token:
(Upon successful authentication these attributes go into an enrollment request)
Enrollment
authMgrImplName
Specifies the name of the authentication plug-in module that
authenticated the request.
Enrollment
authMgrInstName
Specifies the name of the authentication instance that
authenticated the request.
Table 18-2
Attributes supported by request object implementations (Continued)
Request type
Variable name
Description
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...