Subject Alternative Name Extension Default
445
Policy Set Token
Description
$request.auth_token.userid$
The value of the user ID attribute for the user who requested the certificate.
$request.uid$
The value of the user ID attribute for the user who requested the certificate.
$request.profileRemoteAddr$
The IP address of the user making the request. This can be an IPv4 or an IPv6 address, depending on the client. An IPv4
address must be in the format
n.n.n.n
or
n.n.n.n,m.m.m.m
. For example,
128.21.39.40
or
128.21.39.40,255.255.255.00
. An
IPv6 address uses a 128-bit namespace, with the IPv6 address separated by colons and the netmask separated by periods.
For example,
0:0:0:0:0:0:13.1.68.3
,
FF01::43
,
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:255.255.255.0
, and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:0000
.
$request.profileRemoteHost$
The hostname or IP address of the user's machine. The hostname can be the fully-qualified domain name
and the protocol, such as
http://server.example.com
. An IPv4 address must be in the format
n.n.n.n
or
n.n.n.n,m.m.m.m
. For example,
128.21.39.40
or
128.21.39.40,255.255.255.00
. An IPv6 address uses a 128-
bit namespace, with the IPv6 address separated by colons and the netmask separated by periods. For example,
0:0:0:0:0:0:13.1.68.3
,
FF01::43
,
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:255.255.255.0
, and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:0000
.
$request.requestor_email$
The email address of the person who submitted the request.
$request.requestowner$
The person who submitted the request.
$request.subject$
The subject name DN of the entity to which the certificate is issued. For example,
uid=jsmith, [email protected]
.
$request.tokencuid$
The card unique ID (CUID) of the smart card token used for requesting the enrollment.
$request.upn$
The Microsoft UPN. This has the format
(UTF8String)1.3.6.1.4.1.311.20.2.3,$request.upn$
.
$server.source$
Instructs the server to generate a version 4 UUID (random number) component in the subject name. This always has the format
(IA5String)1.2.3.4,$server.source$
.
Table B.15. Variables to Insert Values in the Subject Alternative Name
Multiple attributes can be set for a single extension. The
subjAltNameNumGNs
parameter controls
how many of the listed attributes are required to be added to the certificate. This parameter must
be added to custom profiles and may need modified in default profiles to include as many attributes
as required. In
Example B.1, “Default Subject Alternative Name Extension Configuration”
, the
subjAltNameNumGNs
is set to
3
to insert the
RFC822Name
,
DNSName
, and
URIName
names (generic
names
_0
,
_1
, and
_2
).
The following constraints can be defined with this default:
• Extension Constraint; see
Section B.2.3, “Extension Constraint”
.
• No Constraints; see
Section B.2.6, “No Constraint”
.
Parameter
Description
Critical
Select
true
to mark this extension critical; select
false
to mark the extension noncritical.
Pattern
Specifies the request attribute value to include in
the extension. The attribute value must conform
to any of the supported general name types.
If the server finds the attribute in the request,
it sets the attribute value in the extension and
adds the extension to certificates. If multiple
attributes are specified and none of the attributes
are present in the request, the server does not
add the Subject Alternative Name extension to
certificates. The permissible value is a request
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...