Keyalgorithmconstraints Plug-In Module; Configuration Parameters Of Keyalgorithmconstraints - Netscape MANAGEMENT SYSTEM 4.5 - PLUG-IN Manual

Table of Contents

Advertisement

KeyAlgorithmConstraints Plug-in Module

For details on individual parameters defined in the rule, see Table 3-4 on page 98.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section "Step 2. Modify Existing Policy Rules" in Chapter 18,
"Setting Up Policies" of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section "Step 4. Add New Policy Rules" in the
same chapter.
KeyAlgorithmConstraints Plug-in Module
The
plug-in module implements the key algorithm
KeyAlgorithmConstraints
constraints policy. This policy restricts the key algorithm requested in certificates to
the algorithms, such as RSA and DSA, supported by Certificate Management
System. In other words, this policy allows you to set restrictions on the types of
public keys certified by Certificate Management System.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify only those public keys that
comply with the PKCS-1 RSA Encryption Standard, you can configure the server
for that using the policy.
During installation, Certificate Management System automatically creates an
instance of the key algorithm constraints policy. See "KeyAlgRule Rule" on
page 101.
Configuration Parameters of
KeyAlgorithmConstraints
In the CMS configuration file, the
module is identified
KeyAlgorithmConstraints
as
<subsystem>.Policy.impl.KeyAlgorithmConstraints.class=
, where
com. netscape.certsrv.policy.KeyAlgorithmConstraints
is
or
(prefix identifying the subsystem).
<subsystem>
ca
ra
In the CMS window, the module is identified as
.
KeyAlgorithmConstraints
Figure 3-5 shows how the configurable parameters for the module are displayed in
the CMS window.
Chapter 3
Constraints Policy Plug-in Modules
99

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 4.5

Table of Contents