Configuring Policy Rules for a Subsystem
590
Netscape Certificate Management System Installation and Setup Guide • October 2001
•
Step 6. Restart the Server
•
Step 7. Test Policy Configuration
For information on adding or changing policy-specific information in the
configuration file, see “Changing the Configuration by Editing the Configuration
File” on page 349.
Step 1. Before You Begin
Before configuring a Certificate Manager’s or Registration Manager’s policy, be
sure to do this:
•
Refer to the X.509 standard and PKIX standard RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) to get familiar with certificate
content, including extensions.
•
Read Chapter 3, “Constraints Policy Plug-in Modules” and Chapter 4,
“Certificate Extension Plug-in Modules” of CMS Plug-ins Guide. Determine the
rules that you want to use to govern the generation and formulation of
certificates in your PKI setup. To locate an online version of this book, see
“Where to Go for Related Information” on page 28.
This planning will help you configure a Certificate Manager and Registration
Manager with the appropriate policy rules so that your end entities get the right
kind of certificate.
Step 2. Modify Existing Policy Rules
You can modify a policy rule by editing its configuration parameter values; you
cannot edit the name of a rule. To change the name of a rule, you need to create a
new rule exactly like the rule you want to rename, except with a new name, and
delete the old rule.
As a part of editing a rule, you can change its status from enabled to disabled or
vice versa by checking or unchecking the
enable
parameter. A subsystem subjects
certificate requests only to those rules that are enabled.
During installation, the Certificate Manager and Registration Manager
automatically create a set of policy rules (that you would most likely want to use)
using the policy modules registered by default. Figure 18-1 shows the policy rules
created for a Certificate Manager. The Registration Manager also has a similar list.
Table 18-3 summarizes the default rules created for both Certificate Manager and
Registration Manager.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...