Authoritykeyidentifierext Rule; Basicconstraintsext Plug-In Module - Netscape MANAGEMENT SYSTEM 6.01 - PLUG-IN Manual

Table of Contents

Advertisement

BasicConstraintsExt Plug-in Module

AuthorityKeyIdentifierExt Rule

The rule named
AuthorityKeyIdentifierExt
automatically creates this rule during installation. By default, the rule is configured
as follows:
The rule is enabled.
The predicate expression is left blank so that the extension gets added to all
certificates the server issues.
The extension is marked noncritical (to comply with the PKIX
recommendation).
The rule specifies that a SHA-1 hash of the CA's subject public key info be used
if the CA certificate does not have a Subject Key Identifier extension
(
For details on individual parameters defined in the rule, see Table 4-3 on page 143.
You need to review this rule and make the changes appropriate for your PKI setup.
For instructions, see section "Step 2. Modify Existing Policy Rules" in Chapter 18,
"Setting Up Policies" of CMS Installation and Setup Guide. For instructions on
adding additional instances, see section "Step 4. Add New Policy Rules" in the
same chapter.
BasicConstraintsExt Plug-in Module
The
BasicConstraintsExt
extension policy. This policy enables you to configure Certificate Management
System to add the Basic Constraints Extension defined in X.509 and PKIX standard
RFC 2459 (see
extension identifies whether the Certificate Manager is a CA. In addition, the
extension is also used during the certificate chain verification process to identify
CA certificates and to apply certificate chain-path length constraints.
You should consider adding this extension to all CA certificates (root as well as
subordinate) issued by Certificate Management System. The current PKIX
standard requires that this extension be marked critical and that it appear in all CA
certificates. The standard also recommends that the extension should not appear in
end-entity certificates. For general guidelines on setting the basic constraints
extension, see "basicConstraints" on page 341.
144
Netscape Certificate Management System Plug-Ins Guide • May 2002
AuthorityKeyIdentifierExt
AltKeyIdType=SpkiSHA1
http://www.ietf.org/rfc/rfc2459.txt
is an instance of the
module. Certificate Management System
).
plug-in module implements the basic constraints
) in certificates. The

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents