Chapter 8. Publishing Certificates and CRLs
220
Figure 8.13. Rule Editor Window
•
type
. This is the type of certificate for which the rule applies. For a CA signing certificate, the
value is
cacert
. For a cross-signed certificate, the value is
xcert
. For all other types of
certificates, the value is
certs
. For CRLs, specify
crl
.
•
predicate
. This sets the predicate value for the type of certificate or CRL issuing point to which
this rule applies. The predicate values for CRL issuing points, delta CRLs, and certificates are
listed in
Table 8.3, “Predicate Expressions”
.
•
enable
.
•
mapper
. Mappers are not necessary when publishing to a file; they are only needed for LDAP
publishing. If this rule is associated with a publisher that publishes to an LDAP directory, select
an appropriate mapper here. Leave blank for all other forms of publishing.
•
publisher
. Sets the publisher to associate with the rule.
Table 8.3, “Predicate Expressions”
lists the predicates that can be used to identify CRL issuing points
and delta CRLs and certificate profiles.
Predicate Type
Predicate
CRL Issuing Point
issuingPointId==
Issuing_Point_Instance_ID
&& isDeltaCRl==[true|false]
To publish only the master CRL, set
isDeltaCRl==false
. To publish only the delta CRL, set
isDeltaCRl==true
. To publish
both, set a rule for the master CRL and another rule for the delta CRL.
Certificate Profile
profileId==
profile_name
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...