data:image/s3,"s3://crabby-images/14179/14179d75de3032d6d258af73eeb1c47b9db1af17" alt="Red Hat CERTIFICATE 7.1 ADMINISTRATOR Administrator'S Manual Download Page 540"
Extension-Specific Policy Module Reference
540
Red Hat Certificate System Administrator’s Guide • September 2005
SubjectKeyIdentifierExt
The
SubjectKeyIdentifierExt
plug-in module enables you to add the
Subject
Key
Identifier Extension
to certificates. The extension is used to identify certificates that contain
a particular public key—that is, the extension is used to uniquely identify a certificate from
among several that have the same subject name.
For general information about this extension, see “authorityKeyIdentifier” on page 744.
You can also customize the method for deriving the Key Identifier using the CS SDK by
subclassing the policy and overriding the following method:
formKeyIdentifier(X509CertInfo certInfo, IRequest req)
If enabled, the policy adds a Subject Key Identifier Extension to an enrollment request if the
extension does not already exist. If the extension exists in the request, for example from a
CRMF request, the policy replaces the extension. In case of agent-approved enrollments,
after an agent approves the enrollment request, the policy accepts any Subject Key
Identifier Extension that is already there.
During installation, CS automatically creates an instance of the subject key identifier
extension policy, named
SubjectKeyIdentifierExt
that is enabled by default.
Table 12-41
SubjectKeyIdentifierExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see
“Using Predicates in Policy Rules,” on page 465.
critical
Select if you want the server to mark the extension critical; deselect if you want the server
to mark the extension noncritical (default).
KeyIdentifierType
Specifies the method for deriving Key Identifier.
•
SHA1
specifies that the key identifier must be derived as a 20 byte (160 bit) SHA-1
hash of the BIT STRING of Subject Public Key (default).
•
TypeField
specifies that the key identifier must be derived as a type field value of
0100 followed by 60 least significant bits of the SHA-1 hash of the Subject Public
Key.
•
SpkiSHA1
specifies that the key identifier must be derived as a 20 byte (160 bit)
SHA-1 hash of the Subject Public Key Info.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...