Constraints-Specific Policy Module Reference
Chapter
11
Policies
507
Table 11-13 describes the configuration parameters of the
UniqueSubjectNameConstraints
policy.
Table 11-13
UniqueSubjectNameConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable
(default).
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
enablePreAgent
ApprovalChecki
ng
Specifies whether the request must be checked for the subject name uniqueness on
submission by the user, before the request gets queued for agent approval.
• Select if you want the server to check the certificate request for the subject name
uniqueness as soon as the user submits it.
• Deselect if you want the server to check the certificate request for the subject name
uniqueness after agent approval; that is, you want the policy to be applied to the
request after an agent approves the request. You should choose this option if you
want the server to check the Key Usage extension (see “KeyUsageExt” on
page 535) before determining whether to issue the certificate.
enableKeyUsage
ExtensionCheck
ing
Specifies whether the certificate request must be checked for the Key Usage extension.
Note that the policy can check the certificate request for the Key Usage extension only
if you deselect the
enablePreAgentApprovalChecking
parameter. The reason for
this is that, extensions are set on the request after agent approval, so this checking can
be done after an agent approves the request.
• Select if you want the server to check the certificate request for the Key Usage
extension. If you select, the server checks its internal database for certificates that
have the same subject name as the one specified in the request. For each certificate
that has the matching subject name, the server compares the Key Usage extension
of the certificate to the one specified in the request. If the server finds a certificate
that has the same subject name and Key Usage extension, it rejects request.
Otherwise, the server approves the request. (This choice is suitable if you want to
have multiple certificates with same subject names but for different purposes,
such as signing and encrypting. If key-usage comparison is to be done, be sure to
specify that this policy is to be applied after the Key Usage extension policy.
• Deselect if you don’t want the server to check the certificate request for the Key
Usage extension. If you deselect, the server does not compare the Key Usage
extension in the request with the ones set in the existing certificates that have the
same subject name; it simply rejects requests with same subject names.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...