
Extension-Specific Policy Module Reference
536
Red Hat Certificate System Administrator’s Guide • September 2005
If enabled, the subject alternative extension policy checks the certificate request for
configured attributes. If the request contains an attribute, the policy reads its value and sets
it in the extension. This way, the extension that gets to added to certificates contains all the
configured attributes.
During installation, CS automatically creates an instance of the subject alternative name
extension policy, named
SubjectAltNameExt
, that is enabled by default.
Table 12-39
SubjectAltNameExt Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression,
see“Using Predicates in Policy Rules,” on page 465.
critical
Select to mark critical, deselect to mark noncritical (default).
numGeneralNames
Specifies the total number of alternative names or identities permitted in the extension.
Note that each name has a set of configuration
parameters—
generalName<n>.requestAttr
and
generalName<n>.generalNameChoice
—and you must specify appropriate
values for each of those parameters; otherwise the policy rule will return an error.
You can change the total number of identities by changing the value of this parameter;
there’s no restriction on the total number of identities you can include in the extension.
Each set of configuration parameters is distinguished by
<n>
, which is an integer
derived from the value you assign in this field. For example, if you set the
numGeneralNames
parameter to 2,
<n>
would be
0
and
1
.
•
0
specifies that no identities can be contained in the extension.
•
n
specifies the total number of identities to be included in the extension; it must be
an integer greater than zero. The default value is 8.
generalName<n>.
requestAttr
Specifies the request attribute whose value is to be included in the extension. The
attribute value must conform to any of the supported general-name types (specified by
the
generalName<n>.generalNameChoice
parameter). If the server finds the
attribute in the request, it sets the attribute value in the extension and then adds the
extension to certificates specified by the
predicate
parameter. If you specify multiple
attributes and if none of the attributes are present in the request, the server does not add
the subject alternative name extension to certificates.
Permissible values: A request attribute included in the certificate request.
Example:
AUTH_TOKEN.mail
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...