Chapter 13. Certificate Profiles
308
Parameter
Description
•
-1
specifies that the field should not be set in the extension.
•
0
specifies that no subordinate CA certificates are permitted
in the path before policy mapping is no longer permitted.
•
n
must be an integer that is greater than zero. It specifies at
the maximum number of subordinate CA certificates allowed
in the path before policy mapping is no longer permitted.
For example, a value of 1 indicates that policy mapping may
be processed in certificates issued by the subject of this
certificate, but not in additional certificates in the path.
Table 13.14. Policy Constraints Extension Default Configuration Parameters
13.7.15. Policy Mappers Extension Default
This default attaches a Policy Mappings extension to the certificate. The extension lists pairs of OIDs,
each pair identifying two policy statements of two CAs. The pairing indicates that the corresponding
policies of one CA are equivalent to policies of another CA. The extension may be useful in the context
of cross-certification. If supported, the extension is included in CA certificates only. The default maps
policy statements of one CA to that of another by pairing the OIDs assigned to their policy statements
Each pair is defined by two parameters,
issuerDomainPolicy
and
subjectDomainPolicy
.
The pairing indicates that the issuing CA considers the
issuerDomainPolicy
equivalent
to the
subjectDomainPolicy
of the subject CA. The issuing CA's users may accept an
issuerDomainPolicy
for certain applications. The policy mapping tells these users which policies
associated with the subject CA are equivalent to the policy they accept.
For general information about this extension, see
Section A.3.12, “policyMappings”
.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
critical
Select
true
to mark this extension critical; select
false
to
mark the extension noncritical.
IssuerDomainPolicy_
n
Specifies the OID assigned to the policy statement of the
issuing CA to map with the policy statement of another CA. For
example,
1.2.3.4.5
.
SubjectDomainPolicy_
n
Specifies the OID assigned to the policy statement of the
subject CA that corresponds to the policy statement of the
issuing CA. For example,
6.7.8.9.10
.
Table 13.15. Policy Mappings Extension Default Configuration Parameters
13.7.16. Signing Algorithm Default
This default attaches a signing algorithm in the certificate request. This default presents an agent with
the possible algorithms that can be used for signing the certificate.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...