Key usage bit-specific variables in the SSL server certificate enrollment form
Figure 4-15
ClientCertKeyUsageExt Rule
The policy rule named
module. This rule is for setting the appropriate key-usage bits in SSL client
certificates. By default, the rule is configured as follows:
•
The rule is enabled.
•
The predicate expression (
rule is applied only to SSL client certificate requests.
•
The extension is marked noncritical (to comply with the PKIX
recommendation).
•
The server is configured to set
keyEncipherment
Notice that the key-usage bits specified in the default policy rule match the bits
specified in the enrollment form for requesting SSL client certificates. Figure 4-16
shows the default directory-based enrollment form for end users with the
information related to the key usage extension variables highlighted—it shows
three of the total number of variables listed in Table 4-14 on page 188. Note that by
default three key-usage bits—
—are enabled and the remaining bits are disabled.
keyEncipherment
ClientCertKeyUsageExt
HTTP_PARAMS.certType==client
digitalSignature
key-usage bits in SSL client certificates.
digitalSignature
Chapter 4
KeyUsageExt Plug-in Module
is an instance of the
KeyUsageExt
) ensures that the
,
nonRepudiation
,
, and
nonRepudiation
Certificate Extension Plug-in Modules
, and
197
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 - PLUG-IN and is the answer not in the manual?
Questions and answers