Extension-Specific Policy Module Reference
Chapter
11
Policies
523
For general information about this extension, see “CRLDistributionPoints” on
page 726.
During installation, CMS automatically creates an instance of the CRL distribution
points extension policy, named
CRLDistributionPointsExt
, that is disabled by
default.
Table 11-21
CRLDistributionPointsExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules” on page 485.
critical
Specifies whether the extension should be marked critical or noncritical. Select to
mark critical, deselect to mark noncritical (default).
numPoints
Specifies the total number of CRL distribution points to be contained or allowed in
the extension. Can be set to either
0
specifying that no distribution points can be
contained in the extension or to
n
specifies the total number of distribution points to
be included in the extension; it must be an integer greater than zero. The default is
3
.
Note that when you set a number other than O, each distribution point has its own set
of configuration parameters and you must specify appropriate values for each of
those parameters; otherwise the policy rule will return an error. Each set of
configuration parameters is distinguished by
<n>
, which is an integer derived from
the value you assign in this field. For example, if you set the
numPoints
parameter to
2,
<n>
would be
0
and
1
.
pointName<n>
Specifies the name of the CRL distribution point, the name can be in any of the
following formats:
• An X.500 directory name in the RFC 2253 syntax. For example, the name would
look similar to the subject name in a certificate, like this:
CN=CA Central,
OU=Research Dept, O=Example Corporation, C=US
• A URI; for example, it would look similar to this:
http://testCA.example.com:80
• An
RDN
which specifies a location relative to the CRL Issuer. In this case, the value
of the
pointType
attribute must be
RelativeToIssuer
.
pointType<n>
Specifies the type of the CRL distribution point.
Permissible values:
DirectoryName
,
URI
, or
RelativeToIssuer
. The type you
select must correspond to the value in the
pointName
field.
• Select
DirectoryName
if the value in the
pointName
field is an X.500 directory
name (default).
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...