Extension-Specific Policy Module Reference
552
Netscape Certificate Management System Administrator’s Guide • February 2003
OCSPNoCheckExt
The
OCSPNoCheckExt
plug-in module enables you to add the OCSP No Check
Extension to certificates. The extension, which should be used in OCSP responder
certificates only, indicates how OCSP-compliant applications can verify the
revocation status of the certificate an authorized OCSP responder uses to sign
OCSP responses.
For general information about this extension, see “OCSPNocheck” on page 730.
During installation, CMS automatically creates an instance of the OCSP no check
extension policy, named
OCSPNoCheckExt
, that is enabled by default.
Table 11-33
NSCertTypeExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable
(default).
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see“Using Predicates in Policy Rules,” on page 485.
setDefaultBits
Specifies whether to set the Netscape certificate type extension with default bits in
certificates specified by the predicate expression.
• Select if you want the server to add the extension, with default bits, to certificates.
If you select and if no bits are requested from the HTTP input, the server adds the
Netscape certificate type extension to certificates with the following bits set:
-
ssl client
(bit 0)
-
(bit 2)
• Deselect if you don’t want the server to add the extension with default bits. If you
deselect and if no bits are requested from the HTTP input, the server does not add
the extension to certificates.
Table 11-34
OCSPNoCheckExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see“Using Predicates in Policy Rules,” on page 485.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...