KeyUsageExt Plug-in Module
•
The server is configured to set
in Registration Manager signing certificates. Notice that the key-usage bits
specified in the default policy rule match the bits specified in the enrollment
form (
certificates (see Figure 4-14).
Figure 4-14
ServerCertKeyUsageExt Rule
The policy rule named
module. This rule is for setting the appropriate key-usage bits in SSL server
certificates. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression (
rule is applied only to SSL server certificate requests.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The server is configured to set
keyEncipherment
Notice that the key-usage bits specified in the default policy rule match the bits
specified in the enrollment form (
server certificates (see Figure 4-15).
196
Netscape Certificate Management System Plug-ins Guide • October 2001
) for requesting Registration Manager signing
ManRAEnroll.html
Key usage bit-specific variables in the Registration Manager enrollment form
ServerCertKeyUsageExt
HTTP_PARAMS.certType==server
, and
dataEncipherment
and
digitalSignature
is an instance of the
,
digitalSignature
nonRepudiation
bits in SSL server certificates.
ManServerEnroll.html
bits
nonRepudiation
KeyUsageExt
) ensures that the
,
) for requesting SSL
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 - PLUG-IN and is the answer not in the manual?
Questions and answers