Extension-Specific Policy Module Reference
Chapter
11
Policies
549
NSCertTypeExt
The
NSCertTypeExt
plug-in module enables you to add the Netscape Certificate
Type extension to certificates. The extension identifies the certificate type—for
example, it identifies whether the certificate is a CA certificate, server SSL
certificate, client SSL certificate, object signing certificate, or S/MIME
certificate—and thus enables you to restrict the usage of a certificate to
predetermined purposes.
•
If the extension exists in a certificate, it limits the uses of the certificate to those
specified (it limits the applications for a certificate).
•
If the extension is not present, the certificate can be used for all applications
except object signing.
The Netscape certificate type extension is a string of boolean bit-flags, each bit
identifying the purpose for which a certificate to be used. Table 11-31 lists the bits
and their designated purposes. The extension has no default value.
displayText
Specifies the textual statement that should be included in certificates. If you want to
embed a textual statement (for example, your company’s legal notice) in certificates,
then add that statement here. The text you enter here will be displayed to a relying
party when the certificate is used or viewed.
Permissible values: A string with up to 200 characters.
Example:
Example Corporation’s CPS incorp. by reference liab.
ltd. (c) 2002 Example Corporation
commentfile
Specifies the path to the file that contains the textual statement that should be
included in certificates; be sure to include the complete path, including the filename.
Note that the existence of the file is not checked at the time of policy configuration.
The filename will be checked when the policy is applied to a request.
Example:
/usr/netscape/CApolicies/UserCertpolicy.txt
Table 11-31
Netscape certificate type extension bits and designated purposes
Bit
Purpose
Description
0
SSL Client
Specifies that the certificate can be used by clients for authentication
during SSL connections.
Table 11-30
NSCCommentExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...