
Constraints-Specific Policy Module Reference
488
Red Hat Certificate System Administrator’s Guide • September 2005
During installation, CS automatically creates an instance of the validity constraints policy,
named
DefaultValidityRule
, that is enabled by default.
Table 12-14 describes the configuration parameters of the
ValidityConstraints
policy.
Table 12-14
ValidityConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see “Using
Predicates in Policy Rules” on page 465.
minValidity
Specifies the minimum validity period, in days, for certificates.
maxValidity
Specifies the maximum validity period, in days, for certificates.
leadTime
Specifies the lead time, in minutes, for certificates. For a certificate renewal request to pass the
renewal validity constraints policy, the value of the
notBefore
attribute in the certificate
request must not be more than value of the
leadTime
parameter in the future, relative to the
time when the policy rule is run.
The
notBefore
attribute value specifies the date on which the certificate validity begins;
validity dates through the year 2049 are encoded as
UTCTime
, dates in 2050 or later are
encoded as
GeneralizedTime
.
lagTime
Specifies the lag time, in minutes, for certificates. For a certificate renewal request to pass the
renewal validity constraints policy, the value of the
notBefore
attribute in the certificate
request must not be more than the value of the
lagTime
in the past, relative to the time when
the policy is run.
The
notBefore
attribute value specifies the date on which the certificate validity ends;
validity dates through the year 2049 are encoded as
UTCTime
, dates in 2050 or later are
encoded as
GeneralizedTime
.
notBeforeSkew
Specifies the number of minutes to subtract from the current time when creating the value for
the certificate’s
notBefore
attribute. It can help some clients with incorrectly set clocks use
the new certificate after downloading. For example, if the certificate is issued at 11:30 a.m.
and the clock settings of the client into which the certificate is downloaded is 11:20 a.m., the
certificate cannot be used for 10 minutes. Setting the value of the
beforeFix
parameter to
10 minutes would adjust the value of the
notBefore
parameter to 11:20 a.m.—thus making
the certificate usable following the download.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...