Codesigningext Rule - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

Table 4-10 Description of parameters defined in the ExtendedKeyUsageExt module (Continued)
Parameter
Description
Specifies the OID that identifies a key-usage purpose.
id<n>
Permissible values: A unique, valid OID specified in the dot-separated numeric
component notation. Depending on the key-usage purposes, you may choose to use
the OIDs designated by PKIX (listed in Table 4-9 on page 170) or define your own
OIDs. If you're defining your own OID, it should be in the registered subtree of IDs
reserved for your company's use. Although you can invent your own OIDs for the
purposes of evaluating and testing this server, in a production environment, you
should comply with the ISO rules for defining OIDs and for registering subtrees of
IDs. See
OIDs.
Example: 2.16.840.1.113730.1.99

CODESigningExt Rule

The rule named
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is set (
so that the extension gets added to object signing certificates only—these
certificates are used for signing objects.
The extension is marked noncritical (to comply with the PKIX
recommendation).
The extension contains a single key-usage purpose, which is identified by an
OID (
is designated for code signing.
Note that this policy rule must remain enabled if you want Certificate Management
System to issue object signing certificates with the correct extended key usage
extension.
For details on individual parameters defined in the rule, see Table 4-10 on
page 172. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section "Step 2. Modify Existing Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section "Step 4. Add New Policy
Rules" in the same chapter.
Appendix B, "Object Identifiers"
CODESigningExt
id0=1.3.6.1.5.5.7.3.3
for information on allocating private
is an instance of the
ExtendedKeyUsageExt
HTTP_PARAMS.certType==codeSignClient
). As shown in Table 4-9 on page 170, this OID
Chapter 4
Certificate Extension Plug-in Modules
ExtendedKeyUsageExt Plug-in Module
)
173

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents