Revocationconstraintsrule Rule - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

The configuration shown in Figure 3-8 creates a policy rule named
RevokeExpiredClientCert
revocation of expired client certificates.
Table 3-8 gives details about each of the parameters.
Description of parameters defined in the RevocationConstraints module
Table 3-8
Parameter
enable
predicate
allowExpiredCerts

RevocationConstraintsRule Rule

The rule named
RevocationConstraints
creates this rule during installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is left blank so that the policy is applied to all
certificate revocation requests processed by the server.
The server allows revocation of expired certificates.
, which specifies that the server should allow
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server
verifies the validity period of the certificate being revoked, checks the value
assigned to the allowExpiredCerts parameter, and accordingly allows or
denies the revocation request.
• If you disable the rule, the server does not verify the validity period of the
certificate being revoked; it simply revokes the certificate.
Specifies the predicate expression for this rule. If you want the rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see section "Using Predicates in Policy Rules" in Chapter 18, "Setting
Up Policies" of CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==client
Specifies whether to allow or prevent revocation of expired certificates. Check the
box if you want the server to revoke expired certificates (default). Uncheck the
box if you don't want the server to revoke expired certificates.
RevocationConstraintsRule
module. Certificate Management System automatically
RevocationConstraints Plug-in Module
is an instance of the
Chapter 3
Constraints Policy Plug-in Modules
109

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents