Constraints-Specific Policy Module Reference
506
Netscape Certificate Management System Administrator’s Guide • February 2003
During installation, CMS automatically creates an instance of the subordinate CA
name constraints policy, named
SubCANameConstraints
, that is enabled by
default.
Table 11-12 describes the configuration parameters of the
SubCANameConstraints
policy.
UniqueSubjectNameConstraints
The
UniqueSubjectNameConstraints
plug-in module restricts the server from
issuing multiple certificates with same subject names. Optionally, you can also
configure the server to allow multiple certificates with the same subject name if the
key usages are different. Note that key usages for certificates are usually specified
by the key usage extension and CMS allows you to add this extension to certificates
using the key usage extension policy explained in “KeyUsageExt” on page 535.
You may apply the unique subject name constraints policy to end-entity certificate
enrollment and renewal requests. For example, if you want to prevent your users
from requesting multiple certificates with same subject names, you can configure
the server accordingly using the policy. Alternatively, if you want to allow your
users to own multiple certificates, each for a different use, all having the same
subject name, you can do so easily using the
enableKeyUsageExtensionChecking
parameter defined in this policy. This parameter makes the server check whether
the key usages specified in the certificate request being processed is different than
those specified in the existing certificates that have the same subject names and
accordingly issue or deny the certificate. Keep in mind that the server can check for
key usages only if the key usage extension bits are set in the certificate request
being processed as well as in the existing certificates that have the same subject
names.
During installation, CMS automatically creates an instance of the unique subject
name constraints policy, named
UniqueSubjectNameConstraints
, that is disabled
by default.
Table 11-12
SubCANameConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable
(default).
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...