RevocationConstraints Plug-in Module
Chapter
3
Constraints Policy Plug-in Modules
107
The configuration shown in Figure 3-8 creates a policy rule named
RevokeExpiredClientCert
, which specifies that the server should allow
revocation of expired client certificates.
Table 3-8 gives details about each of the parameters.
RevocationConstraintsRule Rule
The rule named
RevocationConstraintsRule
is an instance of the
RevocationConstraints
module. Certificate Management System automatically
creates this rule during installation. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression is left blank so that the policy is applied to all
certificate revocation requests processed by the server.
•
The server allows revocation of expired certificates.
Table 3-8
Description of parameters defined in the RevocationConstraints module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server
verifies the validity period of the certificate being revoked, checks the value
assigned to the
allowExpiredCerts
parameter, and accordingly allows or
denies the revocation request.
• If you disable the rule, the server does not verify the validity period of the
certificate being revoked; it simply revokes the certificate.
predicate
Specifies the predicate expression for this rule. If you want the rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see section “Using Predicates in Policy Rules” in Chapter 18, “Setting
Up Policies” of CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==client
allowExpiredCerts
Specifies whether to allow or prevent revocation of expired certificates. Check the
box if you want the server to revoke expired certificates (default). Uncheck the
box if you don’t want the server to revoke expired certificates.
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...