Rsakeyrule Rule - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

RSAKeyConstraints Plug-in Module
Description of parameters defined in the RSAKeyConstraints module (Continued)
Table 3-9
Parameter
Description
Specifies the minimum length, in bits, for the key (the length of the modulus in bits).
minSize
The value must be smaller than or equal to the one specified by the maxSize
parameter.
In general, a longer key size results in a key pair that is more difficult to crack. You
may want to allow a minimum length to ensure a minimum level of security.
Permissible values: 512, 1024, 2048, or 4096. You may also enter a custom key size
that is between 512 and 4096 bits. The default value is 512.
Example: 512
Specifies the maximum length, in bits, for the key.
maxSize
Permissible values: 512, 1024, 2048, or 4096. You may also enter a custom key size
that is between 512 and 4096 bits. The default value is 2048.
Example: 1024
Limits the possible public exponent values. Use commas to separate different values.
exponents
Some exponents are more widely used than others. The following exponent values
are recommended for arithmetic and security reasons: 17 and 65537. Of these two
values, 65537 is preferred. (This setting is mainly an issue if you are using your own
software for generating key pairs. Key-generation programs in Netscape clients and
servers use 3 or 65537.)
Permissible values: A combination of 3, 7, 17, and 65537, separated by commas. The
default value is 3,7,17,65537.
Example: 17,65537

RSAKeyRule Rule

The rule named
Certificate Management System automatically creates this rule during installation.
By default, the rule is configured as follows:
The rule is disabled; for the rule to be effective, it must be enabled and
configured appropriately.
The predicate expression is left blank so that the rule is applied to all certificate
enrollment and renewal requests processed by the server.
The minimum key size permitted for certificates is 512 bits (
112
Netscape Certificate Management System Plug-ins Guide • October 2001
is an instance of the
RSAKeyRule
RSAKeyConstraints
minSize=512
module.
).

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents