Attributes for Predicates
Attributes for predicates can come from any of the following:
•
Input form—that is, the HTML form that end entities use for submitting certificate
requests.
•
Authentication token—what the authentication subsystem returns after successfully
authenticating an end entity.
•
A service—for example, a Certificate Manager, Registration Manager, or Data
Recovery Manager service can add certain attributes to the end-entity request.
•
Policy processor—what the policy subsystem returns after subjecting the end-entity
request to policy checking. For example, an extension-based policy can set an
appropriate extension in the certificate.
Table 12-2 lists default attributes that are supported by various request object
implementations.
Table 12-2
Attributes supported by request object implementations
Request type
Variable name
Default attributes from an input form:
Enrollment
requestFormat
Description
Specifies the certificate request format. Default values include the
following:
• keygen
• pkcs10
• clientAuth
Introduction to Policy
Chapter 12
Policies
467
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?