
Extension-Specific Policy Module Reference
Chapter 12
Policies
529
During installation, CS automatically creates an instance of the Netscape certificate type
extension policy for the various types of certificates that you may want the server to issue,
named
NSCertTypeExt
, that is enabled by default.
Additionally, the default enrollment forms—the directory-based, directory- and PIN-based,
manual, and Kerberos server-based enrollment forms—for various types of certificates also
include the appropriate HTTP input variables corresponding to Netscape certificate type
extension bits. For details about these forms.
Note that the default enrollment forms embed variables that are considered appropriate for
the type of certificate, such as client, server, or CA, that can be requested using the form.
For example, the server enrollment form embeds the
ssl_server
variable, whereas the
subordinate CA (Certificate Manager) enrollment form embeds the
ssl_client
,
email_ca
,
ssl_ca
and
object_signing_ca
variables.
In general, the forms are set up so that you don’t have to make any modifications. However,
if there is a need to modify the bit settings, be sure to add or remove the corresponding
variable. Also, when adding a new variable, make sure that the HTML input format is as
follows:
<input type="HIDDEN" value="true" name="variable_name">
where
variable_name
can be any of the variables listed in Table 12-32.
object_signing
Object Signing (bit 3)
Reserved for future use (bit 4)
ssl_ca
SSL CA (bit 5)
email_ca
S/MIME CA (bit 6)
object_signing_ca
Object Signing CA (bit 7)
Table 12-33
NSCertTypeExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable (default).
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see“Using
Predicates in Policy Rules,” on page 465.
Table 12-32
HTTP input variables for
Netscape certificate
type extension bits
(Continued)
HTTP input variable
Netscape certificate type extension bit
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...