Chapter 13. Certificate Profiles
312
Parameter
Description
Enable
Sets whether that attribute is able to be added to the
certificate. Select
true
to enable the attribute.
Table 13.18. Subject Directory Attributes Extension Default Configuration Parameters
13.7.19. Subject Key Identifier Extension Default
This default attaches a Subject Key Identifier extension to the certificate. The extension identifies
certificates that contain a particular public key, which identifies a certificate from among several that
have the same subject name.
For general information about this extension, see
Section A.3.16, “subjectKeyIdentifier”
.
If enabled, the profile adds a Subject Key Identifier Extension to an enrollment request if the extension
does not already exist. If the extension exists in the request, such as a CRMF request, the default
replaces the extension. After an agent approves the manual enrollment request, the profile accepts
any Subject Key Identifier Extension that is already there.
This default has no parameters. If used, this extension is included in the certificate with the public key
information.
The following constraints can be defined with this default:
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
13.7.20. Subject Name Default
This default attaches a server-side configurable subject name to the certificate request. A static
subject name is used as the subject name in the certificate.
The following constraints can be defined with this default:
• Subject Name Constraint; see
Section 13.8.9, “Subject Name Constraint”
.
• Unique Subject Name Constraint; see
Section 13.8.10, “Unique Subject Name Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Parameter
Description
Name
Specify the subject name for this certificate.
Table 13.19. Subject Name Default Configuration Parameters
If you need to get a certificate subject name that uses the DNPATTERN value from the UidPwdDirAuth
plugin, then configure the profile to use the Subject Name Default plugin and substitute the
Name
parameter with the "Subject Name" from the
AuthToken
as shown below.
policyset.userCertSet.1.default.class_id=subjectNameDefaultImpl
policyset.userCertSet.1.default.name=Subject Name Default
policyset.userCertSet.1.default.params.name=$request.auth_token.tokenCertSubject$
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...