Subjectkeyidentifierext Rule - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

SubjectKeyIdentifierExt Plug-in Module
Table 4-28 Description of configuration parameters defined in the SubjectKeyIdentifierExt module
Parameter
predicate
critical
KeyIdentifierType

SubjectKeyIdentifierExt Rule

The policy rule named
SubjectKeyIdentifierExt
automatically creates this rule during installation. By default, the rule is configured
as follows:
The rule is enabled.
The predicate expression is set (
that the extension gets added to CA certificates only. (PKIX and Federal PKI
standards recommend that CA certificates must have this extension and
end-entity certificates should have this extension.)
The key identifier is a 20 byte (160 bit) SHA-1 hash of the BIT STRING of
Subject Public Key (
246
Netscape Certificate Management System Plug-ins Guide • October 2001
Description
Specifies the predicate expression for this rule. If you want this rule to be applied
to all certificate requests, leave the field blank (default). To form a predicate
expression, see section "Using Predicates in Policy Rules" in Chapter 18, "Setting
Up Policies" of CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==ca
Specifies whether the extension should be marked critical or noncritical in
certificates specified by the predicate parameter. Check the box if you want
the server to mark the extension critical. Uncheck the box if you want the server
to mark the extension noncritical (default).
Specifies the method for deriving Key Identifier.
Permissible values: SHA1, TypeField, or SpkiSHA1.
• SHA1 specifies that the key identifier must be derived as a 20 byte (160 bit)
SHA-1 hash of the BIT STRING of Subject Public Key (default).
• TypeField specifies that the key identifier must be derived as a type field
value of 0100 followed by 60 least significant bits of the SHA-1 hash of the
Subject Public Key.
• SpkiSHA1 specifies that the key identifier must be derived as a 20 byte (160
bit) SHA-1 hash of the Subject Public Key Info.
Example: SHA1
SubjectKeyIdentifierExt
KeyIdentifierType=SHA1
module. Certificate Management System
predicate=HTTP_PARAMS.certType==ca
is an instance of the
).
) so

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents