Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual page 111

Table of Contents

Advertisement

Figure 3-9
The configuration shown in Figure 3-9 creates a policy rule named
RSAKeySizeForClientCert
the minimum and maximum key sizes for all RSA key-based client certificates to
512 and 2048, respectively.
Table 3-9 describes each parameter.
Description of parameters defined in the RSAKeyConstraints module
Table 3-9
Parameter
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
enable
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server uses
• If you disable the rule, the server certifies the requested key size.
Specifies the predicate expression for this rule. If you want the rule to be applied to all
predicate
certificate requests, leave the field blank (default). To form a predicate expression, see
section "Using Predicates in Policy Rules" in Chapter 18, "Setting Up Policies" of
CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==client
Parameters of the RSAKeyConstraints module
the configured RSA key rules when issuing certificates specified by the
predicate parameter.
, which enforces a rule that the server should restrict
Chapter 3
RSAKeyConstraints Plug-in Module
Constraints Policy Plug-in Modules
111

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents