Extension-Specific Policy Module Reference
Chapter
11
Policies
513
AuthorityKeyIdentifierExt
The
AuthorityKeyIdentifierExt
plug-in module enables you to add the
Authority Key Identifier Extension to certificates. The extension is used to identify the
public key that corresponds to the private key used by a CA to sign certificates.
For general information about this extension, see “authorityKeyIdentifier” on
page 724.
For information on setting the subject key identifier extension in certificates, see
“SubjectKeyIdentifierExt” on page 562.
• If you selected
URL
, the value must be a non-relative universal resource identifier
(URI) following the URL syntax and encoding rules. That is, the name must
include both a scheme (for example,
http
) and a fully qualified domain name or
IP address of the host. For example,
http://ocspResponder.example.com:8000
• If you selected
iPAddress
, the value must be a valid IP address specified in
dot-separated numeric component notation. The syntax for specifying the IP
address is as follows:
IPv4 address must be in the
n.n.n.n
format; for example,
128.21.39.40
. IPv4
address with netmask must be in the
n.n.n.n,m.m.m.m
format. For example,
128.21.39.40,255.255.255.00
.
For IP version 6 (IPv6), the address should be in the form with netmask separated
by a comma. Examples of IPv6 addresses with no netmask are
0:0:0:0:0:0:13.1.68.3
and
FF01::43
. Examples of IPv6 addresses with
netmask are
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FFFF:
FFFF:255.255.255.0
and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:0000
.
• If you selected
OID
, the value must be a unique, valid OID specified in
dot-separated numeric component notation. Although you can invent your own
OIDs for the purposes of evaluating and testing this server, in a production
environment, you should comply with the ISO rules for defining OIDs and for
registering subtrees of IDs. See <<<XREF
Appendix B, “Object
Identifiers”>>>
for information on allocating private OIDs. For example,
1.2.3.4.55.6.5.99
.
• If you selected
otherName
, the value must be the absolute path to the file
containing the base-64 encoded string of the location. For example,
/usr/netscape/servers/ext/aia/othername.txt
.
Table 11-15
AuthInfoAccessExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...