Extension-Specific Policy Module Reference
560
Netscape Certificate Management System Administrator’s Guide • February 2003
Before you edit the default rule, you should read the additional details about the
attributes that are set in the default policy rule.
The first two attributes,
AUTH_TOKEN.mail
and
AUTH_TOKEN.mailalternateaddress
, are standard LDAP attributes typically used
for storing end users’ email addresses in an LDAP directory. These attributes
enable you to include a user’s email address as an alternative name in the
certificate. Remember that you need to specify the LDAP attribute for users’ email
addresses as a part of configuring the server to use a specific directory for
authentication—which means for the default rule to set end users’ email addresses
in the subject alternative name extension, you must ensure the following:
•
The server is configured for directory-based, directory- and PIN-based, or NIS
server based (using directory attributes for forming subject names) enrollment;
that is, you have created and configured an authentication instance.
•
The
ldapStringAttributes
parameter in the authentication instance is set to
or
mailalternateaddress
, or to both.
The third attribute,
HTTP_PARAMS.csrRequestorEmail
, is the email component of
the subject name in an enrollment request—it is an HTTP input value that gets
added to the request when a user uses the manual enrollment form; for details.
• Select
dNSName
if the request-attribute value is a DNS name. For example,
corpDirectory.example.com
.
• Select
ediPartyName
if the request-attribute value is a EDI party name. For
example,
Example Corporation
.
• Select
URL
if the request-attribute value is a non-relative URI that includes
both a scheme (for example,
http
) and a fully qualified domain name or IP
address of the host. For example,
http://hr.example.com
.
• Select
iPAddress
if the request-attribute value is a valid IP address
specified in dot-separated numeric component notation. For example,
128.21.39.40
.
• Select
OID
if the request-attribute value is a unique, valid OID specified in
the dot-separated numeric component notation. For example,
1.2.3.4.55.6.5.99
.
• Select
otherName
if the request-attribute value is the absolute path to the
file that contains the base-64 encoded string of the subject alternative name.
For example,
/usr/netscape/servers/ext/san/othername.txt
.
Table 11-39
SubjectAltNameExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...