![Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Скачать руководство пользователя страница 336](http://html.mh-extra.com/html/red-hat/certificate-system-7-3-administration/certificate-system-7-3-administration_administration-manual_1427433336.webp)
Chapter 13. Certificate Profiles
314
• If this extension is set on a profile with a corresponding OID (Extension Constraint), then any
certificate request processed through that profile
must
carry the specified extension or the request is
rejected.
A certificate
request
that contains the user-defined extensions must be submitted to the profile. The
certificate enrollment forms, however, do not have any input fields for users to add user-supplied
extensions. Submitting a certificate request without supplying the extension fails.
The following constraints can be defined with this default:
• Basic Constraints Extension Constraint; see
Section 13.8.1, “Basic Constraints Extension
Constraint”
.
• Extended Key Usage Constraint; see
Section 13.8.2, “Extended Key Usage Extension Constraint”
.
• Extension Constraint; see
Section 13.8.3, “Extension Constraint”
.
• Key Constraints; see
Section 13.8.4, “Key Constraint”
.
• Netscape Certificate Type Extension Constraint; see
Section 13.8.7, “Netscape Certificate Type
Extension Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
This example adds the User Supplied Extension Default to a profile with the Basic Constraints
Extension Constraint. The OID specified in the
userExtOID
parameter is for the Basic Constraints
Extension Constraint.
policyset.set1.p5.default.params.keyUsageNonRepudiation=true
policyset.set1.p6.constraint.class_id=basicConstraintsExtConstraintImpl
policyset.set1.p6.constraint.name=Basic Constraint Extension Constraint
policyset.set1.p6.constraint.params.basicConstraintsCritical=true
policyset.set1.p6.constraint.params.basicConstraintsIsCA=false
policyset.set1.p6.constraint.params.basicConstraintsMinPathLen=-1
policyset.set1.p6.constraint.params.basicConstraintsMaxPathLen=-1
policyset.set1.p6.default.class_id=userExtensionDefaultImpl
policyset.set1.p6.default.name=User Supplied Extension Default
policyset.set1.p6.default.params.userExtOID=2.5.29.19
Editing profiles is described in
Section 13.3.2, “Modifying Certificate Profiles through the Command
Line”
.
13.7.23. User Supplied Key Default
This default attaches a user-supplied key into the certificate request. This is a required default. Keys
are part of the enrollment request.
The following constraints can be defined with this default:
• Key Constraint; see
Section 13.8.4, “Key Constraint”
.
• No Constraints; see
Section 13.8.6, “No Constraint”
.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...