Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual page 104

Table of Contents

Advertisement

RenewalValidityConstraints Plug-in Module
Figure 3-7
The configuration shown in Figure 3-7 creates a policy rule named
RenewalRuleForClientCert
only those client certificates that are due to expire within the next 15 days. The
renewed certificates are valid for at least 60 days (two months) and require
renewing after 180 days (six months).
Table 3-7 gives details about each of the parameters.
Table 3-7
Description of parameters defined in the RenewalValidityConstraints module
Parameter
enable
predicate
104
Netscape Certificate Management System Plug-Ins Guide • March 2002
Parameters of the RenewalValidityConstraints module
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server sets
the configured validity period in renewed certificates specified by the
predicate parameter.
• If you disable the rule, the server sets the validity period as specified in the
renewal request.
Specifies the predicate expression for this rule. If you want the rule to be applied to
all certificate requests, leave the field blank (default). To form a predicate
expression, see section "Using Predicates in Policy Rules" in Chapter 18, "Setting Up
Policies" of CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==client
, which enforces a rule that the server should renew

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents