SubjectAltNameExt Plug-in Module
232
Netscape Certificate Management System Plug-Ins Guide • March 2002
SubjectAltNameExt Plug-in Module
The
SubjectAltNameExt
plug-in module implements the subject alternative name
policy. This policy enables you to configure Certificate Management System to add
the Subject Alternative Name Extension defined in X.509 and PKIX standard RFC
2459 (see
http://www.ietf.org/rfc/rfc2459.txt
) to certificates. The extension
enables you to bind additional identities—such as Internet electronic mail address,
a DNS name, an IP address, and a uniform resource indicator (URI)—to the subject
of the certificate.
The standard suggests that if the certificate subject field contains an empty
sequence, then the subject alternative name extension must contain the subject’s
alternative name and that the extension be marked critical. For general guidelines
on setting the subject alternate name extension in certificates, see
“subjectAltName” on page 354.
The subject alternative name extension policy in Certificate Management System
enables you to include values of certificate-request attributes in the extension. You
can include any number of attributes as long as the attribute values conform to any
of the supported general-name forms: rfc822Name, X.500 directory name, DNS
name, EDI party name, URL, IP address, object identifier, and Other name.
Table 4-25
Description of parameters defined in the RemoveBasicConstraintsExt module
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Check the box to enable the
rule (default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server
checks certificate requests for Basic Constraints extension and removes it.
• If you disable the rule, the server does not check the requests for Basic
Constraints extension; it ignores the values in the remaining fields.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see section “Using Predicates in Policy Rules” in Chapter 18, “Setting
Up Policies” of CMS Installation and Setup Guide.
Example:
HTTP_PARAMS.certType==client
Содержание Certificate Management System 6.0
Страница 1: ...Plug Ins Guide Netscape Certificate Management System Version6 0 March 2002...
Страница 10: ...10 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 126: ...ValidityConstraints Plug in Module 126 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 266: ...LdapSubjAttrMap Plug in Module 266 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 324: ...DNs in Certificate Management System 324 Netscape Certificate Management System Plug Ins Guide March 2002...
Страница 370: ...CA Certificates and Extension Interactions 370 Netscape Certificate Management System Plug Ins Guide March 2002...