Subjectaltnameext Rule - Netscape MANAGEMENT SYSTEM 6.01 - PLUG-IN Manual

Table of Contents

Advertisement

SubjectAltNameExt Rule

The policy rule named
SubjectAltNameExt
creates this rule during installation. By default, the rule is configured as follows:
The rule is enabled.
The predicate expression is left blank so that the extension gets added to all
certificates the server issues. (PKIX and Federal PKI standards recommend that
CA certificates must have this extension and end-entity certificates should
have this extension.)
The extension is marked noncritical (to comply with the PKIX
recommendation).
The rule is configured to include at the most three alternative names in the
extension (
numGeneralNames=3
The first alternative name is the value of the
subject's directory entry (
and the name is in the
(
generalName0.generalNameChoice=rfc822Name
The second alternative name is the value of the
attribute in the certificate subject's directory entry
(
generalName1.requestAttr=AUTH_TOKEN.mailalternateaddress
name is in the
rfc822Name
(
generalName1.generalNameChoice=rfc822Name
The third alternative name is the value of an HTTP input parameter
csrRequestorEmail
(
generalName2.requestAttr=HTTP_PARAMS.csrRequestorEmail
name is in
rfc822Name
(
generalName2.generalNameChoice=rfc822Name
For details on individual parameters defined in the rule, see Table 4-26 on
page 235. You need to review this rule and make the changes appropriate for your
PKI setup. For instructions, see section "Step 2. Modify Existing Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Installation and Setup Guide. For
instructions on adding additional instances, see section "Step 4. Add New Policy
Rules" in the same chapter.
Before you edit the default rule, you should read the additional details about the
attributes that are set in the default policy rule.
SubjectAltNameExt
module. Certificate Management System automatically
).
generalName0.requestAttr=AUTH_TOKEN.mail
format
rfc822Name
format
included in the certificate request
format
Chapter 4
SubjectAltNameExt Plug-in Module
is an instance of the
attribute in the certificate
mail
).
mailalternateaddress
).
).
Certificate Extension Plug-in Modules
)
) and the
) and the
237

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents