Constraints-Specific Policy Module Reference
Chapter
11
Policies
503
RSAKeyConstraints
The
RSAKeyConstraints
plug-in module imposes constraints on the following:
•
The minimum and maximum sizes for keys
•
The exponent sizes
The policy restricts the key size to one of the sizes supported by CMS—512, 1024,
2048, or 4096. In other words, the policy allows you to set up restrictions on the
lengths of public keys certified by CMS.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify public keys up to 1024 bits in
length for end users, you can configure the server accordingly using the policy.
During installation, CMS automatically creates an instance of the RSA key
constraints polic, named
RSAKeyRule
, that is disabled by default.
Table 11-10 describes the configuration parameters of the
RSAKeyConstraints
policy.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see “Using Predicates in Policy Rules” on page 485.
allowExpiredCerts
Specifies whether to allow or prevent revocation of expired certificates. Select if
you want the server to revoke expired certificates (default). Deselect if you don’t
want the server to revoke expired certificates.
Table 11-10
RSAKeyConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable the rule (default).
Deselect to disable the rule.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
Table 11-9
RevocationConstraints Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...