
RenewalValidityConstraints Plug-in Module
Chapter
3
Constraints Policy Plug-in Modules
105
DefaultRenewalValidityRule Rule
The rule named
DefaultRenewalValidityRule
is an instance of the
RenewalValidityConstraints
module. Certificate Management System
automatically creates this rule during installation. By default, the rule is configured
as follows:
•
The rule is enabled.
•
The predicate expression is left blank so that the policy is applied to all
certificate renewal requests processed by the server.
•
The minimum validity period permitted for renewed certificates is 30 days
(
minValidity=30
).
•
The maximum validity period permitted for renewed certificates is 365 days
(
maxValidity=365
).
•
The number of days before expiration that end entities can renew their
currently valid certificates is 15 (
renewalInterval=15
).
For details on individual parameters defined in the rule, see Table 3-7 on page 104.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section “Step 2. Modify Existing Policy Rules” in Chapter 18,
“Setting Up Policies” of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section “Step 4. Add New Policy Rules” in the
same chapter.
minValidity
Specifies the minimum validity period, in days, for renewed certificates.
Permissible values: As applicable. The default value is 180 days.
Example:
60
maxValidity
Specifies the maximum validity period, in days, for renewed certificates.
Permissible values: As applicable. The default value is 730 days.
Example:
180
renewalInterval
Specifies how many days before its expiration that a certificate can be renewed.
Permissible values: As applicable. The default value is 15 days.
Example:
15
Table 3-7
Description of parameters defined in the RenewalValidityConstraints module (Continued)
Parameter
Description
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...