Extension-Specific Policy Module Reference
Chapter
11
Policies
555
extension may be useful in the context of cross-certification. If supported, the
extension is to be included in CA certificates only. The policy allows you to map
policy statements of one CA to that of another by pairing the OIDs assigned to their
policy statements
Each pair is defined by two parameters,
issuerDomainPolicy
and
subjectDomainPolicy
. The pairing indicates that the issuing CA considers the
issuerDomainPolicy
equivalent to the
subjectDomainPolicy
of the subject CA.
The issuing CA’s users may accept an
issuerDomainPolicy
for certain
applications. The policy mapping tells these users which policies associated with
the subject CA are equivalent to the policy they accept.
For general information about this extension, see “policyMappings” on page 731.
During installation, CMS automatically creates an instance of the policy mappings
extension policy, named
PolicyMappingsExt
, that is enabled by default.
Table 11-36
PolicyMappingsExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be
applied to all certificate requests, leave the field blank (default). To form a
predicate expression, see “Using Predicates in Policy Rules,” on page 485.
critical
Select to mark critical, deselect to mark noncritical (default).
numPolicyMappings
Specifies the total number of policy mapping (pairs) to be contained or allowed
in the extension. Note that each policy mapping represents a pair of
policies—specified by
policyMap<n>.issuerDomainPolicy
and
policyMap<n>.subjectDomainPolicy
—and each policy in the pair
belongs to a specific CA.
You can change the total number of policy pairs by changing the value
assigned to this parameter; there’s no restriction on the total number of policy
pairs you can include in the extension. Each pair is distinguished by
<n>
,
which is an integer derived from the value you assign in this field. For
example, if you set the
numPolicyMappings
parameter to 2,
<n>
would be
0
and
1
.
Permissible values:
0
or
n
.
•
0
specifies that no policy pairs can be contained in the extension.
•
n
specifies the total number of policy pairs to be included in the extension;
it must be a integer greater than zero. The default value is
1
.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...