Renewalconstraints - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Constraints-Specific Policy Module Reference
Table 12-6 describes the configuration parameters of the
policy.
Table 12-6
KeyAlgorithmConstraints Configuration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to disable.
enable
Specifies the predicate expression for this rule. If you want this rule to be applied to all
predicate
certificate requests, leave the field blank (default). To form a predicate expression, see "Using
Predicates in Policy Rules" on page 465.
Specifies the key type the server should certify. The default is RSA.
algorithms
Permissible values: RSA or RSA.

RenewalConstraints

The
RenewalConstraints
certificates—it allows or restricts the server from renewing expired certificates. You may
apply this policy to end-entity certificate renewal requests.
During installation, CS automatically creates an instance of the renewal constraints policy,
named
Table 12-7 describes the configuration parameters of the
Table 12-7
RenewalConstraints Configuration Parameters
Parameter
enable
predicate
allowExpiredCerts
renewalNotAfter
480
Red Hat Certificate System Administrator's Guide • September 2005
plug-in module imposes constraints on renewal of expired
RenewalConstraintsRule
Description
Specifies whether the rule is enabled or disabled. Select to enable the rule (default).
Deselect to disable the rule.
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see
"Using Predicates in Policy Rules" on page 465.
Specifies whether to allow or prevent renewal of expired certificates. Select if you want
the server to renew expired certificates (default). Deselect if you don't want the server to
renew expired certificates.
Specifies how long, in days, after the expiration of a certificate can it be renewed. The
default value is 30 days. If you leave the field blank, the server will renew all expired
certificates that are submitted for renewal.
KeyAlgorithmConstraints
, that is enabled by default.
RenewalConstraints
policy.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents