
Constraints-Specific Policy Module Reference
Chapter 12
Policies
481
RenewalValidityConstraints
The
RenewalValidityConstraints
plug-in module governs the formulation of content
in the renewed certificate based on the currently issued certificate.
The renewal validity constraints policy enables you to enforce certain restrictions on
certificate-renewal requests, when end entities attempt to renew their certificates.
During installation, CS automatically creates an instance of the renewal validity constraints
policy, named
DefaultRenewalValidityRule
, that is enabled by default.
Table 12-8 describes the configuration parameters of the
RenewalValidityConstraints
policy.
RevocationConstraints
The
RevocationConstraints
plug-in module imposes constraints on revocation of
expired certificates—it allows or restricts the server from revoking expired certificates. You
may apply this policy to end-entity certificate revocation requests.
During installation, CS automatically creates an instance of the revocation constraints
policy, named
RevocationConstraintsRule
, that is enabled by default.
Table 12-9 describes the configuration parameters of the
RevocationConstraints
policy.
Table 12-8
RenewalValidityConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see
“Using Predicates in Policy Rules” on page 465.
minValidity
Specifies the minimum validity period, in days, for renewed certificates.
maxValidity
Specifies the maximum validity period, in days, for renewed certificates.
renewalInterval
Specifies how many days before its expiration that a certificate can be renewed.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...