Extension-Specific Policy Module Reference
554
Netscape Certificate Management System Administrator’s Guide • February 2003
PolicyMappingsExt
The
PolicyMappingsExt
plug-in module enables you to add the Policy Mappings
Extension defined to certificates. The extension lists one or more pairs of OIDs, each
pair identifying two policy statements of two CAs. The pairing indicates that the
corresponding policies of one CA are equivalent to policies of another CA. The
reqExplicit
Policy
Specifies the total number of certificates permitted in the path before an explicit
policy is required—that is, the number of CA certificates that can be chained below
(subordinate to) the subordinate CA certificate being issued before an acceptable
policy is required.
Note that the number you specify affects the number of CA certificates to be used
during certificate validation. The chain starts with the end-entity certificate being
validated and moving up the chain. (The parameter has no effect if the extension is set
in end-entity certificates.)
Permissible values:
-1
,
0
, or
n
.
•
-1
specifies that the field should not be set in the extension (default).
•
0
specifies that no subordinate CA certificates are permitted in the path before an
explicit policy is required.
•
n
must be an integer that is greater than zero. It specifies at the most
n
subordinate CA certificates are allowed in the path before an explicit policy is
required.
inhibitPolicy
Mapping
Specifies the total number of certificates permitted in the path before policy mapping
is no longer permitted.
Permissible values:
-1
,
0
, or
n
.
•
-1
specifies that the field should not be set in the extension (default).
•
0
specifies that no subordinate CA certificates are permitted in the path before
policy mapping is no longer permitted.
•
n
must be an integer that is greater than zero. It specifies at the most
n
subordinate CA certificates are allowed in the path before policy mapping is no
longer permitted. For example, a value of one indicates that policy mapping may
be processed in certificates issued by the subject of this certificate, but not in
additional certificates in the path.
Table 11-35
PolicyConstraintsExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...