
Defaults Reference
432
Red Hat Certificate System Administrator’s Guide • September 2005
CRL Distribution Points Extension Default
This default populates the CRL Distribution points extension in the certificate request. This
extension, when present in a certificate, identifies one or more locations from which an
application that is validating the certificate can obtain the CRL information (to verify the
revocation status of the certificate).
For general information about this extension, see “CRLDistributionPoints” on page 733.
You can define the following constraints with this default:
•
Extension Constraint, see “Extension Constraint,” on page 454
•
No Constraints, see “No Constraint,” on page 456
This default allows you to define 5 locations and specify parameters for each location. The
parameters are marked with an
<n>
in the table to distinguish that the parameter is
associated with one of the five possible locations.
•
n
must be an integer greater than zero. It specifies at the most n
subordinate CA certificates are allowed below the subordinate CA
certificate being used.
If you leave the field blank, the path length defaults to a value that is
determined by the path length set in the Basic Constraints extension in
the issuer’s certificate. If the issuer’s path length is unlimited, the path
length in the subordinate CA certificate will also be unlimited. If the
issuer’s path length is an integer greater than zero, the path length in
the subordinate CA certificate will be set to a value that’s one less than
the issuer’s path length; for example, if the issuer’s path length is 4,
the path length in the subordinate CA certificate will be set to 3.
Table 11-3
CRL Distribution Points Extension Configuration Parameters
Parameter
Description
Critical
Select true to mark this extension critical; select false to mark
the extension noncritical.
Type_<n>
Specifies the type of the CRL distribution point.
Permissible values:
DirectoryName
,
URIName
, or
RelativeToIssuer
. The type you select must correspond
to the value in the
Name
field.
Table 11-2
Basic Constraints Extension Default Configuration Parameters
(Continued)
Parameter
Description
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...