Extension-Specific Policy Module Reference
520
Netscape Certificate Management System Administrator’s Guide • June 2003
CRLDistributionPointsExt
The
CRLDistributionPointsExt
plug-in module enables you to add the CRL
Distribution Points Extension to certificates. This extension, when present in a
certificate, identifies one or more locations from where the application that is
validating the certificate can obtain the CRL information (to verify the revocation
status of the certificate).
• If you selected
ediPartyName
, the value must be an IA5String. For
example,
Example Corporation
.
• If you selected
URL
, the value must be a non-relative URI, including both a
scheme (for example,
http
) and a fully qualified domain name or IP
address of the host. For example,
http://webSite.example.com
.
• If you selected
iPAddress
, the value must be a valid IP address specified in
dot-separated numeric component notation. The syntax for specifying the IP
address is as follows:
IPv4 address must be in the
n.n.n.n
format; for example,
128.21.39.40
.
IPv4 address with netmask must be in the
n.n.n.n,m.m.m.m
format. For
example,
128.21.39.40,255.255.255.00
.
For IP version 6 (IPv6), the address should be in the form with netmask
separated by a comma. Examples of IPv6 addresses with no netmask are
0:0:0:0:0:0:13.1.68.3
and
FF01::43
. Examples of IPv6 addresses
with netmask are
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FFFF:
FFFF:255.255.255.0
and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:0000
.
• If you selected
OID
, the value must be a unique, valid OID specified in
dot-separated numeric component notation. Although you can invent your
own OIDs for the purposes of evaluating and testing this server, in a
production environment, you should comply with the ISO rules for defining
OIDs and for registering subtrees of IDs. See
Appendix H, “Object
Identifiers”
for information on allocating private OIDs. For example,
1.2.3.4.55.6.5.99
.
• If you selected
otherName
, the value must be the absolute path to the file
that contains the base-64 encoded string for the site. For example,
/usr/netscape/servers/ext/aia/othername.txt
.
entry<n>_port_
number
Specifies the port number.
Example: 8888
Table 11-20
CertificateScopeOfUseExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...