Table 11-15 Subject Alternative Name Extension Default Configuration Parameters (Continued)
Parameter
Description
•
Select DNSName if the request-attribute value is a DNS name. For example,
corpDirectory.example.com.
•
Select EDIPartyName if the request-attribute value is a EDI party name. For
example, Example Corporation.
•
Select URLName if the request-attribute value is a non-relative URI that
includes both a scheme (for example, http) and a fully qualified domain
name or IP address of the host. For example, http://hr.example.com.
•
Select IPAddress if the request-attribute value is a valid IP address
specified in dot-separated numeric component notation. For example,
128.21.39.40.
•
Select OIDName if the request-attribute value is a unique, valid OID specified
in the dot-separated numeric component notation. For example,
1.2.3.4.55.6.5.99.
Subject Key Identifier Extension Default
This default populates a subject key identifier extension in the certificate request. The
extension is used to identify certificates that contain a particular public key—that is, the
extension is used to uniquely identify a certificate from among several that have the same
subject name.
For general information about this extension, see "subjectKeyIdentifier" on page 741.
If enabled, the policy adds a Subject Key Identifier Extension to an enrollment request if the
extension does not already exist. If the extension exists in the request, for example from a
CRMF request, the default replaces the extension. In case of agent-approved enrollments,
after an agent approves the enrollment request, the policy accepts any Subject Key
Identifier Extension that is already there.
This default has not parameters. If used, this extension will be included in the certificate
with the public key information.
You can define the following constraints with this default:
•
Extension Constraint, see "Extension Constraint," on page 454.
•
No Constraints, see "No Constraint," on page 456.
Defaults Reference
Chapter 11
Certificate Profiles
449
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?