Objsigncertkeyusageext Rule - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

KeyUsageExt Plug-in Module
Each of these forms embed HTTP input variables (for key-usage bits) that are
considered appropriate for the certificate being requested using that form. If you
want, you may create additional instances of the key usage extension policy, one
each for each client certificate enrollment form and configure these instances as
appropriate. Be sure to use the correct predicate expression to distinguish the
certificates to thus avoid setting incorrect bits.

ObjSignCertKeyUsageExt Rule

The policy rule named
KeyUsageExt
object signing certificates. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression
(
is applied to only object signing certificate requests.
The extension is marked noncritical (to comply with the PKIX
recommendation).
The server is configured to set
object-signing certificates. Notice that the key-usage bits specified in the
default policy rule match the bits specified in the enrollment form
(
Figure 4-17).
Figure 4-17
198
Netscape Certificate Management System Plug-Ins Guide • March 2002
ObjSignCertKeyUsageExt
module. This rule is for setting the appropriate key-usage bits in
predicate=HTTP_PARAMS.certType==objSignClient
ManObjSignEnroll.html
Key usage extension bits in the object signing certificate enrollment form
is an instance of the
digitalSignature
) for requesting object-signing certificates (see
) ensures that the rule
and
bits in
keyCertsign

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents