Extension-Specific Policy Module Reference
Chapter
11
Policies
537
During installation, CMS automatically creates multiple instances of the key usage
extension policy suitable for various types of certificates that you may want the
server to issue. The default instances are named as follows:
•
CMCertKeyUsageExt
This rule is for setting the appropriate key-usage bits in
Certificate Manager CA signing certificates and is enabled by default.
The server is configured to set
digitalSignature
,
nonRepudiation
,
keyCertsign
, and
cRLSign
bits in CA signing certificates. Notice that the
key-usage bits specified in the default policy rule match the bits specified in the
enrollment form (
ManCAEnroll.html
) for requesting CA signing certificates.
•
RMCertKeyUsageExt
This rule is for setting the appropriate key-usage bits in
Registration Managers’ signing certificates and is enabled by defualt.
The server is configured to set
digitalSignature
and
nonRepudiation
bits in
Registration Manager signing certificates. Notice that the key-usage bits
specified in the default policy rule match the bits specified in the enrollment
form (
ManRAEnroll.html
) for requesting Registration Manager signing
certificates.
•
ServerCertKeyUsageExt
This rule is for setting the appropriate key-usage
bits in SSL server certificates and is enabled by default.
The server is configured to set
digitalSignature
,
nonRepudiation
,
keyEncipherment
, and
dataEncipherment
bits in SSL server certificates.
Notice that the key-usage bits specified in the default policy rule match the bits
specified in the enrollment form (
ManServerEnroll.html
) for requesting SSL
server certificates.
•
ClientCertKeyUsageExt
This rule is for setting the appropriate key-usage
bits in SSL client certificates and is enabled by default.
•
ObjSignCertKeyUsageExt
This rule is for setting the appropriate key-usage
bits in object signing certificates and is enabled by default.
The server is configured to set
digitalSignature
and
keyCertsign
bits in
object-signing certificates. Notice that the key-usage bits specified in the
default policy rule match the bits specified in the enrollment form
(
ManObjSignEnroll.html
) for requesting object-signing certificates.
•
CRLSignCertKeyUsageExt
This rule is for setting the appropriate key-usage
bits in a CRL signing certificate and is enabled by default.
The server is configured to set the
cRLSign
bit in CRL signing certificates.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...