Extension-Specific Policy Module Reference
Chapter
11
Policies
561
If you enable the default policy rule, the server automatically checks the certificate
request for attributes
AUTH_TOKEN.mail
,
AUTH_TOKEN.mailalternateaddress
,
and
HTTP_PARAMS.csrRequestorEmail
. If the server finds any of the attributes, it
sets the attribute value in the extension and then adds the extension to certificates
specified by the
predicate
parameter. If none of the attributes are in a request, the
server does not add the subject alternative name extension to the certificate.
SubjectDirectoryAttributesExt
The
SubjectDirectoryAttributesExt
plug-in module enables you to add the
Subject Directory Attributes Extension to certificates. The extension is used to specify
any desired directory attribute values for the subject of the certificate.
For general information about this extension, see “subjectDirectoryAttributes” on
page 733.
The subject directory attributes extension policy in CMS allows you to include up
to three directory attributes in the extension. For each attribute that you want to
include in the extension, you need to specify the attribute name and its value—the
name must be the X.500 directory attribute name itself and the attribute value can
be derived from the request or directly entered in the policy configuration as a
string value.
The list of directory attributes supported by default are shown as permissible
values for the
attribute<n>.attributeName
parameter explained in Table 11-40
on page 561. You can extend the list of attributes supported by the policy by
defining new X.500 directory attributes. For details on defining new attributes, see
“Extending Attribute Support” on page 752.
Note that, during installation, CMS does not create an instance of the subject
directory attributes extension policy. If you want the server to add this extension to
certificates, you must create an instance of the
SubjectDirectoryAttributesExt
module and configure it.
Table 11-40
SubjectDirectoryAttributesExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be
applied to all certificate requests, leave the field blank (default). To form a
predicate expression, see “Using Predicates in Policy Rules,” on page 485.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...