AuthorityKeyIdentifierExt Plug-in Module
Chapter
4
Certificate Extension Plug-in Modules
143
The configuration shown in Figure 4-3 creates a policy rule named
AuthKeyIDExtForCACert
, which enforces a rule that the server should set the
authority key identifier extension in all CA certificates.
Table 4-3 gives details about each of these parameters.
Table 4-3
Description of parameters defined in the AuthorityKeyIdentifierExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server adds
the authority key identifier extension to certificates specified by the
predicate
parameter.
• If you disable the rule, the server does not add the extension to certificates; it
ignores the values in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see section “Using Predicates in Policy Rules” in Chapter 18, “Setting Up Policies” of
CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==ca
critical
Specifies whether the extension should be marked critical or noncritical in certificates
specified by the
predicate
parameter. Check the box if you want the server to mark
the extension critical. Uncheck the box if you want the server to mark the extension
noncritical (default).
AltKeyIdType
Specifies what should be done if the CA certificate does not have a Subject Key
Identifier extension.
Permissible values:
SpkiSHA1
or
None
.
• Select
SpkiSHA1
if you want the server to use a SHA-1 hash of the CA’s subject
public key information (default).
• Select
None
if you don’t want the server to set the authority key identifier
extension in certificates.
Example:
SpkiSHA1
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...