Extension-Specific Policy Module Reference
514
Netscape Certificate Management System Administrator’s Guide • February 2003
During installation, CMS automatically creates an instance of the authority key
identifier extension policy, named
AuthorityKeyIdentifierExt
, that is enabled
by default.
BasicConstraintsExt
The
BasicConstraintsExt
plug-in module enables you to add the Basic
Constraints Extension in certificates. The extension identifies whether the Certificate
Manager is a CA. The extension is also used during the certificate chain verification
process to identify CA certificates and to apply certificate chain-path length
constraints.
For general information about this extension, see “basicConstraints” on page 725.
During installation, CMS automatically creates an instance of the basic constraints
extension policy, named
BasicConstraintsExt
, that is enabled by default.
Table 11-16
AuthorityKeyIdentifierExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
critical
Specifies whether the extension should be marked critical or noncritical. Select to
mark critical, deselect to mark noncritical (default).
AltKeyIdType
Specifies what should be done if the CA certificate does not have a Subject Key
Identifier extension. Select either of the following:
• Select
SpkiSHA1
if you want the server to use a SHA-1 hash of the CA’s subject
public key information (default).
• Select
None
if you don’t want the server to set the authority key identifier
extension in certificates.
Table 11-17
BasicConstraintsExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...