Extension-Specific Policy Module Reference
554
Netscape Certificate Management System Administrator’s Guide • June 2003
PrivateKeyUsagePeriodExt
The
PrivateKeyUsagePeriodExt
plug-in module enables you to add the Private
Key Usage Period Extension to certificates. The extension allows the certificate issuer
to specify a different validity period for the private key than the one specified for
the corresponding certificate. The extension is intended for use with digital
signature keys.
For general information about this extension, see “privateKeyUsagePeriod” on
page 766.
policyMap<n>.
issuerDomainPolicy
Specifies the OID assigned to the policy statement
<n>
of the issuing CA that
you want to map with the policy statement of another CA.
Permissible values: Any valid OID specified in dot-separated numeric
component notation (see the example). The OID that you specify should be in
the registered subtree of IDs reserved for your company’s use. Although you
can invent your own OIDs for the purposes of evaluating and testing this
server, in a production environment, you should comply with the ISO rules for
defining OIDs and for registering subtrees of IDs. See Appendix H, “Object
Identifiers
”
for information on allocating private OIDs.
Example:
1.2.3.4.5
policyMap<n>.
subjectDomainPolicy
Specifies the OID assigned to the policy statement
<n>
of the subject CA that
corresponds to the policy statement of the issuing CA.
Permissible values: Any valid OID specified in dot-separated numeric
component notation (see the example).
Example:
6.7.8.9.10
Table 11-37
PrivateKeyUsagePeriodExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate expression,
see “Using Predicates in Policy Rules,” on page 483.
critical
Select to mark critical, deselect to mark noncritical (default).
Table 11-36
PolicyMappingsExt Configuration Parameters (Continued)
Parameter
Description
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...