Basicconstraintsext - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Table 12-16 AuthorityKeyIdentifierExt Configuration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
enable
Specifies the predicate expression for this rule. If you want this rule to be applied to all
predicate
certificate requests, leave the field blank (default). To form a predicate expression, see "Using
Predicates in Policy Rules" on page 465.
Specifies whether the extension should be marked critical or noncritical. Select to mark
critical
critical, deselect to mark noncritical (default).
Specifies what should be done if the CA certificate does not have a Subject Key Identifier
AltKeyIdType
extension. Select either of the following:

BasicConstraintsExt

The
BasicConstraintsExt
Extension in certificates. The extension identifies whether the Certificate Manager is a CA.
The extension is also used during the certificate chain verification process to identify CA
certificates and to apply certificate chain-path length constraints.
For general information about this extension, see "basicConstraints" on page 732.
During installation, CS automatically creates an instance of the basic constraints extension
policy, named
Table 12-17 BasicConstraintsExt Configuration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable, deselect to disable.
enable
Specifies the predicate expression for this rule. If you want this rule to be applied to all
predicate
certificate requests, leave the field blank (default). To form a predicate expression, see "Using
Predicates in Policy Rules" on page 465.
Specifies whether the extension should be marked critical or noncritical. Select to mark critical
critical
(default), deselect to mark noncritical.
Select SpkiSHA1 if you want the server to use a SHA-1 hash of the CA's subject public
key information (default).
Select None if you don't want the server to set the authority key identifier extension in
certificates.
BasicConstraintsExt
plug-in module enables you to add the Basic Constraints
, that is enabled by default.
Extension-Specific Policy Module Reference
Chapter 12
Policies
493

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents