Ocspnocheckext Rule - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

Table 4-21 Description of parameters defined in the OCSPNoCheckExt module
Parameter
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
enable
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server adds
• If you disable the rule, the server does not add the extension to certificates; it
Specifies the predicate expression for this rule. If you want this rule to be applied to
predicate
all certificate requests, leave the field blank (default). To form a predicate expression,
see section "Using Predicates in Policy Rules" in Chapter 18, "Setting Up Policies" of
CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==ocspResponder
Specifies whether the extension should be marked critical or noncritical in certificates
critical
specified by the predicate parameter. Check the box if you want the server to mark
the extension critical. Uncheck the box if you want the server to mark the extension
noncritical (default).

OCSPNoCheckExt Rule

The policy rule named
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is set
(
gets added to OCSP responder certificates only.
The extension is marked noncritical (to comply with the PKIX
recommendation).
For details on individual parameters defined in the rule, see Table 4-21 on
page 221. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section "Step 2. Modify Existing Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section "Step 4. Add New Policy
Rules" in the same chapter.
the OCSP no check extension to certificates specified by the predicate
parameter.
ignores the values in the remaining fields.
OCSPNoCheckExt
predicate=HTTP_PARAMS.certType==ocspResponder
OCSPNoCheckExt Plug-in Module
is an instance of the
OCSPNoCheckExt
) so that the extension
Chapter 4
Certificate Extension Plug-in Modules
221

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents