CRL Extension Reference
Chapter
14
Revocation and CRLs
611
HoldInstruction
The
HoldInstruction
rule enables you to configure a Certificate Manager to set
the CRL Hold Instruction Extension in CRL entries. The extension is a non-critical
CRL entry extension that is used to specify a registered instruction identifier—the
identifier indicates what action the validating application should take when it
encounters a certificate that has been placed on hold.
For general guidelines on setting the CRL hold instruction code in CRL entries, see
“holdInstructionCode” on page 740.
pointName<n>
• If
pointType
is set to
directoryName
, the value must be a
string in the form of X.500 name, similar to the subject name in a
certificate. For example,
CN=CACentral,OU=Research
Dept,O=Example Corporation,C=US
.
• If
pointType
is set to
URI
, the name must be a URI; the URI must
be an absolute pathname and must specify the host. For example:
http://testCA.example.com/get/your/crls/here/
Table 14-6
HoldInstruction Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable,
deselect to disable (default).
critical
Select if you want the server to mark the extension critical; deselect
if you want the server to mark the extension noncritical (default).
instruction
Specifies the action a validating application must take when it
encounters a certificate that has been put on hold.
Permissible values:
none
,
callissuer
, or
reject
.
•
none
specifies that the validating application need not do
anything; the PKIX standard says that this is semantically
equivalent to the absence of a holdInstructionCode (default).
•
callissuer
specifies that the validating application must call
the CA that has issued the certificate or reject the certificate.
•
reject
specifies that the validating application must reject the
certificate on hold.
Table 14-5
FreshestCRL Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...