Subcanameconstraints - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Constraints-Specific Policy Module Reference
Table 12-11 describes the configuration parameters of the
SigningAlgorithmConstraints
Table 12-11 SigningAlgorithmConstraintsConfiguration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to disable.
enable
Specifies the predicate expression for this rule. If you want this rule to be applied to all
predicate
certificate requests, leave the field blank (default). To form a predicate expression, see "Using
Predicates in Policy Rules" on page 465.
Specifies the signature algorithm the server should use to sign certificates.
algorithms
Permissible values: Depends on the CA's signing key type (the key type you chose for the
Certificate Manager's CA signing certificate).

SubCANameConstraints

The
SubCANameConstraints
CA certificate that has the same issuer name as that of the CA itself—that is, the policy
prevents a situation where the signing certificates of a CA and its subordinate CA have
identical issuer names.
This policy must be turned on if you're planning to issue subordinate CA certificates.
Whenever the Certificate Manager issues a certificate, it stores the related information in its
internal database; if the CA issues a subordinate CA certificate with an issuer DN that
matches its own issuer DN, the internal database will not function properly.
You may apply this policy to CA certificate enrollment and renewal requests.
During installation, CS automatically creates an instance of the subordinate CA name
constraints policy, named
484
Red Hat Certificate System Administrator's Guide • September 2005
If the key type is RSA, select one of the following:
- MD2withRSA,MD5withRSA,SHA1withRSA
- MD2withRSA,MD5withRSA
- MD2withRSA,SHA1withRSA
- MD5withRSA,SHA1withRSA
- MD2withRSA
- MD5withRSA
- SHA1withRSA
The default value is MD2withRSA,MD5withRSA,SHA1withRSA.
If the key type is DSA, select SHA1withDSA.
SubCANameConstraints
policy.
plug-in module restricts a CA from issuing a subordinate
, that is enabled by default.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents