Extension-Specific Policy Module Reference
Chapter
11
Policies
519
CertificateScopeOfUseExt
The
CertificateScopeOfUseExt
plug-in module enables you to add the Certificate
Scope of Use Extension to certificates. The extension enables you to specify a list of
web sites that may request the use of a particular certificate for SSL client
authentication, thus aiding certificate-using applications to select certificates to
present to web sites and to control release of these certificates.
relativeEndTime
Specifies the last opportunity for automatic renewal of the certificate that contains
this extension. Specifying a value for this parameter is optional; if you leave the
field blank, the certificate-using application is expected to use the expiration date
(
notAfter
value) in the certificate.
Permissible values:
0
or
n
.
•
0
specifies that the renewal window ends at the same time the certificate
expires; the
endTime
field of the extension will be set to the time the
certificate expires.
•
n
specifies a past or future time, in seconds, by which the certificate must be
renewed; the
endTime
field of the extension will be set to the specified time
since certificate issuance. You can specify the time period in seconds, minutes,
hours, days, or months. Use the following suffixes to indicate the time unit.
s
- seconds
m
- minutes
h
- hours
D
- days
M
- months
For example, if you’re issuing certificates with a validity period of two years and
want the renewal window to end a month after the certificates expire, and want to
specify the interval in months, you would enter
25M
in this field. On the other
hand, if you want the renewal window to end 15 days before certificates expire,
then you would set the value to
705D
((23 months x 30 days) + 15 days).
Note that if you choose to extend the renewal window after the expiration date of
the certificate itself, your CA must maintain appropriate status information about
the certificate during that window in order to allow appropriate authentication in
the renewal process. (Automatic renewal may take place after the certificate has
expired, when it is not valid for other purposes.)
Example:
705D
Table 11-19
CertificateRenewalWindowExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...