Policymappingsext Rule; Privatekeyusageperiodext Plug-In Module - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

PolicyMappingsExt Rule

The rule named
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is set (
that the extension gets added to CA certificates only.
The extension is marked noncritical (to comply with the PKIX
recommendation).
The number of policy mappings is set to 1 (
that a pair of policies are to be mapped.
The fields for entering the OIDs for policies that are to be mapped are left blank
for you to enter the appropriate values.
For details on individual parameters defined in the rule, see Table 4-23 on
page 227. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section "Step 2. Modify Existing Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section "Step 4. Add New Policy
Rules" in the same chapter.

PrivateKeyUsagePeriodExt Plug-in Module

The
PrivateKeyUsagePeriodExt
usage period extension policy. This policy enables you to configure Certificate
Management System to add the Private Key Usage Period Extension defined in X.509
and PKIX standard RFC 2459 (see
certificates. The extension allows the certificate issuer to specify a different validity
period for the private key than the one specified for the corresponding certificate.
The extension is intended for use with digital signature keys.
The PKIX standard recommends against the use of this extension. The standard
also recommends that CAs conforming to the standard must not generate
certificates with private key usage period extensions that are marked critical. For
general guidelines on setting this extension in certificates, see
"privateKeyUsagePeriod" on page 355.
PolicyMappingsExt
predicate=HTTP_PARAMS.certType==ca
plug-in module implements the private key
http://www.ietf.org/rfc/rfc2459.txt
PrivateKeyUsagePeriodExt Plug-in Module
is an instance of the
PolicyMappingsExt
numPolicyMappings=1
Chapter 4
Certificate Extension Plug-in Modules
) so
) indicating
) to
229

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents