Ocspnocheckext Rule - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

OCSPNoCheckExt Plug-in Module
Table 4-21 Description of parameters defined in the OCSPNoCheckExt module
Parameter
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule
enable
(default). Uncheck the box to disable the rule.
• If you enable the rule and set the remaining parameters correctly, the server adds
• If you disable the rule, the server does not add the extension to certificates; it
Specifies the predicate expression for this rule. If you want this rule to be applied to
predicate
all certificate requests, leave the field blank (default). To form a predicate expression,
see section "Using Predicates in Policy Rules" in Chapter 18, "Setting Up Policies" of
CMS Installation and Setup Guide.
Example: HTTP_PARAMS.certType==ocspResponder
Specifies whether the extension should be marked critical or noncritical in certificates
critical
specified by the predicate parameter. Check the box if you want the server to mark
the extension critical. Uncheck the box if you want the server to mark the extension
noncritical (default).

OCSPNoCheckExt Rule

The policy rule named
module. Certificate Management System automatically creates this rule during
installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is set
(
gets added to OCSP responder certificates only.
The extension is marked noncritical (to comply with the PKIX
recommendation).
For details on individual parameters defined in the rule, see Table 4-21 on
page 220. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section "Step 2. Modify Existing Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section "Step 4. Add New Policy
Rules" in the same chapter.
220
Netscape Certificate Management System Plug-Ins Guide • March 2002
the OCSP no check extension to certificates specified by the predicate
parameter.
ignores the values in the remaining fields.
OCSPNoCheckExt
predicate=HTTP_PARAMS.certType==ocspResponder
is an instance of the
OCSPNoCheckExt
) so that the extension

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents