Extension-Specific Policy Module Reference
Chapter
11
Policies
515
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
critical
Specifies whether the extension should be marked critical or noncritical. Select to
mark critical (default), deselect to mark noncritical.
isCA
Specifies whether the certificate subject is a CA. If you select the option, the server
checks the
maxPathLen
parameter and sets the specified path length in the
certificate. If you deselect the option, the server treats the certificate subject as a
non-CA and ignores the value specified for the
maxPathLen
parameter.
maxPathLen
Specifies the path length, the maximum number of CA certificates that may be
chained below (subordinate to) the subordinate CA certificate being issued. Note that
the path length you specify affects the number of CA certificates to be used during
certificate validation. The chain starts with the end-entity certificate being validated
and moving up the chain.
The
maxPathLen
parameter has no effect if the extension is set in end-entity
certificates.
Permissible values:
0
or
n
. Make sure that the value you choose is less than the path
length specified in the Basic Constraints extension of the CA signing certificate
(owned by the CA that will issue these certificates).
•
0
specifies that no subordinate CA certificates are allowed below the subordinate
CA certificate being issued—that is, only an end-entity certificate may follow in
the path.
•
n
must be an integer greater than zero. It specifies at the most n subordinate CA
certificates are allowed below the subordinate CA certificate being used.
• If you leave the field blank, the path length defaults to a value that is determined
by the path length set on the Basic Constraints extension in the issuer’s certificate.
If the issuer’s path length is unlimited, the path length in the subordinate CA
certificate will also be unlimited. If the issuer’s path length is an integer greater
than zero, the path length in the subordinate CA certificate will be set to a value
that’s one less than the issuer’s path length; for example, if the issuer’s path length
is 4, the path length in the subordinate CA certificate will be set to 3.
Table 11-17
BasicConstraintsExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...