No Constraint; Netscape Certificate Type Extension Constraint; Renewal Grace Period Constraint - Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Parameter
decipherOnly
Table B.23. Key Usage Extension Constraint Configuration Parameters
B.2.6. No Constraint
This constraint implements no constraint. When chosen along with a default, there are not constraints
placed on that default.
B.2.7. Netscape Certificate Type Extension Constraint
WARNING
This constraint is obsolete. Instead of using the Netscape Certificate Type extension
constraint, use the Key Usage extension or Extended Key Usage extension.
The Netscape Certificate Type extension constraint checks if the Netscape Certificate Type extension
in the certificate request satisfies the criteria set in this constraint.
B.2.8. Renewal Grace Period Constraint
The Renewal Grace Period Constraint sets rules on when a user can renew a certificate based on its
expiration date. For example, users cannot renew a certificate until a certain time before it expires or if
it goes past a certain time after its expiration date.
One important thing to remember when using this constraint is that this constraint is set on the original
enrollment profile, not the renewal profile. The rules for the renewal grace period are part of the
original certificate and are carried over and applied for any subsequent renewals.
This constraint is only available with the No Default extension.
Parameter
renewal.graceAfter
renewal.graceBefore
Table B.24. Renewal Grace Period Constraint Configuration Parameters
Description
false to keep this from being set; select a
hyphen, -, to indicate no constraints are placed
for this parameter.
Specifies whether to set the extension if the
public key is to be used only for deciphering
data. If this bit is set, keyAgreement should
also be set. Select true to allow this to be set;
select false to keep this from being set; select
a hyphen, -, to indicate no constraints are placed
for this parameter.
Description
Sets the period, in days, after the certificate
expires that it can be submitted for renewal. If the
certificate has been expired longer that that time,
then the renewal request is rejected.
Sets the period, in days, before the certificate
expires that it can be submitted for renewal. If the
certificate is not that close to its expiration date,
then the renewal request is rejected.

No Constraint

455

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents