Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual page 586

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Introduction to Policy
Table 18-2 Attributes supported by request object implementations (Continued)
Request type
Variable name
Enrollment
cepsubstore
Enrollment,
requestStatus
Renewal, and
Revocation
Renewal
requestFormat
Default attributes from an authentication token:
(Upon successful authentication these attributes go into an enrollment request)
Enrollment
authMgrImplName
Enrollment
authMgrInstName
You can define your own attributes for predicates, if there's a need. For example,
assume you have two organizational units Sales and Manufacturing and you want
to issue client certificates with different validity periods to users in these two units.
A quick and easy way to accomplish this would be to define a new attribute for the
organizational unit, add the attribute to the enrollment form that the users in these
organizational units use for certificate enrollment (so that the server receives it
from the HTTP input), and use the attribute in the predicate expression for the
validity constraints policy—a policy rule that determines the validity period of
certificates the server issues. For details on this policy, check the
"ValidityConstraints Plug-in Module" section in Chapter 3, "Constraints Policy
Plug-in Modules" of CMS Plug-ins Guide.
586
Netscape Certificate Management System Installation and Setup Guide • October 2001
Description
Specifies the name of the CEP service; for example, cep1 and
cep2. When setting up multiple CEP services, you can use
predicates to differentiate one service for another; see "Step 4.
Set Up Multiple CEP Services" on page 820.
Specifies when (or the phase in which) a request gets
subjected to policy processing:
• begin specifies that the request be subjected to a policy
before it gets queued for agent approval.
• pending specifies that the request be subjected to a
policy after agent approval.
Specifies the certificate request format. Default values
include the following:
• clientAuth
• pkcs10
Specifies the name of the authentication plug-in module that
authenticated the request.
Specifies the name of the authentication instance that
authenticated the request.

Advertisement

Table of Contents
loading

Table of Contents