Extension-Specific Policy Module Reference
550
Netscape Certificate Management System Administrator’s Guide • February 2003
The Netscape certificate type extension policy has been implemented in such a way
that it enables you to set the appropriate certificate-type bits for certificates being
issued by CMS. This way, you can restrict the purposes for which a certificate
should be used by adding the extension, with the appropriate bits set, to the
certificate at the time of issuance. For example, if you want to restrict a certificate to
be used for SSL client authentication only, when issuing the certificate you would
add the Netscape certificate type extension to the certificate with
ssl_client
(bit
0) set. For general guidelines on setting the Netscape certificate type extension, see
“netscape-cert-type” on page 741.
In the current implementation, you can specify whether to add the extension to
certificates on the server side and which bits in the extension are to be set on the
client side—you specify whether to add the extension by enabling the Netscape
certificate type extension policy and which bits are to be set by adding the
appropriate HTTP variables to the enrollment forms.
Bits set in the Netscape certificate type extension are formed from pre-defined
input variables that you can embed as hidden values in the default enrollment
forms. Table 11-32 lists the HTTP input variables that correspond to Netscape
certificate type extension bits.
1
SSL Server
Specifies that the certificate can be used by servers for authentication
during SSL connections.
2
S/MIME
Specifies that the certificate can be used to send secure email
messages.
3
Object Signing
Specifies that the certificate can be used for signing objects such as
Java applets and plug-ins.
4
Reserved
This bit is reserved for future use.
5
SSL CA
Specifies that the certificate can be used by a CA to issue certificates
for SSL connections.
6
S/MIME CA
Specifies that the certificate can be used by a CA to issue certificates
for secure email.
7
Object Signing CA
Specifies that the certificate can be used by a CA to issue certificates
for object signing.
Table 11-31
Netscape certificate type extension bits and designated purposes (Continued)
Bit
Purpose
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...