Authinfoaccessext Rule - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

AuthInfoAccessExt Plug-in Module

AuthInfoAccessExt Rule

The rule named
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
The rule is disabled.
The predicate expression (
ensures that the policy is to be applied to client certificate requests processed
by the server.
The extension is marked noncritical (to comply with the PKIX
recommendation).
The total number of access locations to be contained or allowed in the
extension is set to 1 (
The access method for retrieving additional information about the CA that has
issued the certificate in which the extension appears is set to OCSP
(
The general-name type for the location that contains additional information
about the CA that has issued the certificate in which the extension appears is
set to URL (
The address or location to get additional information about the CA that has
issued the certificate in which this extension appears is left blank for you to
enter the URL at which the OCSP responder will service requests from
OCSP-compliant clients.
Note that if you installed the Certificate Manager with it's built-in OCSP service
enabled, the policy rule will be enabled and the address location (
will be pointed to the Certificate Manager's nonSSL end-entity port. For example, if
the nonSSL end-entity port of your Certificate Manager is 80, the URL would look
like this:
For details on individual parameters defined in the rule, see Table 4-2 on page 135.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section "Step 2. Modify Existing Policy Rules" in Chapter 18,
"Setting Up Policies" of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section "Step 4. Add New Policy Rules" in the
same chapter.
140
Netscape Certificate Management System Plug-Ins Guide • March 2002
AuthInfoAccessExt
numADs=1
).
ad0_method=ocsp
ad0_location_type=URL
http://ocspResponder.example.com:80/ocsp
is an instance of the
predicate=HTTP_PARAMS.certType==client
).
).
AuthInfoAccessExt
)
ad0_location=
)

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents