Policy Constraints Extension Default
307
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
Table 13.13. OCSP No Check Extension Default Configuration Parameters
13.7.14. Policy Constraints Extension Default
This default attaches a Policy Constraints extension to the certificate. The extension, which can be
used in CA certificates only, constrains path validation in two ways: either to prohibit policy mapping
or to require that each certificate in a path contain an acceptable policy identifier. The default can
specify both,
ReqExplicitPolicy
and
InhibitPolicyMapping
. PKIX standard requires that, if
present in a CA certificate, the extension must never consist of a null sequence. At least one of the
two specified fields must be present.
For general information about this extension, see
Section A.3.11, “policyConstraints”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
reqExplicitPolicy
Specifies the total number of certificates permitted in the path
before an explicit policy is required. This is the number of CA
certificates that can be chained below the subordinate CA
certificate before an acceptable policy is required.
•
-1
specifies that the field should not be set in the extension.
•
0
specifies that no subordinate CA certificates are permitted
in the path before an explicit policy is required.
•
n
must be an integer that is greater than zero. It specifies the
maximum number of subordinate CA certificates allowed in
the path before an explicit policy is required.
This number affects the number of CA certificates to be used
during certificate validation. The chain starts with the end-
entity certificate being validated and moving up the chain. The
parameter has no effect if the extension is set in end-entity
certificates.
inhibitPolicyMapping
Specifies the total number of certificates permitted in the path
before policy mapping is no longer permitted.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...