Table 12-29 NameConstraintsExt Configuration Parameters (Continued)
Parameter
permittedSubtrees<n>.
base.generalNameChoice
permittedSubtrees<n>.
base.generalNameValue
Description
Permissible values: 0 or n.
•
0 specifies that no excluded subtrees can be contained in the extension.
•
n specifies the total number of excluded subtrees to be included in the
extension; it must be an integer greater than zero. The default value is 8.
Specifies the general-name type for the permitted subtree you want to include in
the extension.
Permissible values: rfc822Name, directoryName, dNSName,
ediPartyName, URI, iPAddress, registeredID, or otherName.
•
Select rfc822Name if the subtree is an Internet mail address (default).
•
Select directoryName if the subtree is an X.500 directory name.
•
Select dNSName if the subtree is a DNS name.
•
Select ediPartyName if the subtree is a EDI party name.
•
Select URL if the subtree is a uniform resource locator.
•
Select iPAddress if the subtree is an IP address.
•
Select OID if the subtree is an object identifier.
•
Select otherName if the subtree is in any other name form.
Example: directoryName
Specifies the general-name value for the permitted subtree you want to include in
the extension.
Permissible values: Depends on the general-name type you selected in the
permittedSubtrees<n>.base.generalNameChoice field.
•
If you selected rfc822Name, the value must be a valid Internet mail address
in the local-part@domain format; see the definition of an rfc822Name
as defined in RFC 822 (http://www.ietf.org/rfc/rfc0822.txt).
You may use upper and lower case letters in the mail address; no significance
is attached to the case. For example, testCA@example.com.
•
If you selected directoryName, the value must be a string form of X.500
name, similar to the subject name in a certificate, in the RFC 2253 syntax (see
http://www.ietf.org/rfc/rfc2253.txt). Note that RFC 2253
replaces RFC 1779. For example, CN=SubCA, OU=Research Dept,
O=Example Corporation, C=US.
Extension-Specific Policy Module Reference
Chapter 12
Policies
521
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?
Questions and answers