Netscape Certificate Management System (CMS) provides a customizable policy
framework for its main subsystems, the Certificate Manager, Registration
Manager, and Data Recovery Manager. This chapter explains how to configure
these subsystems to apply organizational and other policies on incoming certificate
and key-related requests.
The chapter has the following sections:
•
Introduction to Policy (page 579)
•
Configuring Policy Rules for a Subsystem (page 589)
•
Using JavaScript for Policies (page 602)
•
Managing Policy Plug-in Modules (page 602)
Introduction to Policy
You can configure the main subsystems of Netscape Certificate Management
System (CMS)—the Certificate Manager, Registration Manager, and Data Recovery
Manager—to apply certain organizational policies on an end entity's certificate
enrollment and management requests before servicing them. For example, some of
the policies you might want a Certificate Manager to impose on these requests may
include setting a minimum and maximum limit on validity period and key length
of certificates, setting extensions based on the end entity's role within an
organization, setting signing algorithms, and so on.
This section provides an overview of policy in general. Topics include:
•
What Is Policy?
•
Policy Rules
•
Policy Processor
Setting Up Policies
Chapter 18
579
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 and is the answer not in the manual?