Managing Subject Names and Subject Alternative Names
61
Serial number management can be enabled for CAs which are not cloned, if the
parameters are set in the
CS.cfg
file.
dbs.beginSerialNumber=1
dbs.enableSerialManagement=
true
dbs.endReplicaNumber=100
dbs.endRequestNumber=10000000
dbs.endSerialNumber=10000000
However, by default, serial number management is disabled unless a system is
cloned, when it is automatically enabled.
The serial number range cannot be updated manually through the console. The serial number
ranges are read-only fields. If cloning or serial number management is not enabled, then the
serial number range can be updated by editing the values in the
CS.cfg
file.
•
Default Signing Algorithm.
Specifies the signing algorithm the Certificate Manager
uses to sign certificates. The options are
MD2withRSA
,
MD5withRSA
,
SHA1withRSA
,
SHA256withRSA
, and
SHA512withRSA
, if the CA's signing key type is RSA.
The signing algorithm specified in the certificate profile configuration overrides the algorithm set
here.
4. Click
Save
.
2.7. Managing Subject Names and Subject Alternative
Names
The
subject name
of a certificate is a distinguished name (DN) that contains identifying information
about the entity to which the certificate is issued. This subject name is built from standard LDAP
directory components, such as email addresses, common names, and organizational units. These
components are defined in X.500. In addition to — or even in place of — the subject name, the
certificate can have a
subject alternative name
, which is a kind of extension set for the certificate that
includes additional information that is not defined in X.500.
The naming components for both subject names and subject alternative names can be customized.
IMPORTANT
If the subject name is empty, then the Subject Alternative Name extension must be
present and marked critical.
2.7.1. Inserting LDAP Directory Attribute Values and Other
Information into the Subject Alt Name
Information from an LDAP directory or that was submitted by the requester can be inserted into
the subject alternative name of the certificate by using matching variables in the Subject Alt Name
Extension Default configuration. This default sets the type (format) of information and then the
matching pattern (variable) to use to retrieve the information. For example:
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...