Crlreason Rule - Netscape MANAGEMENT SYSTEM 6.01 - PLUG-IN Manual

Table of Contents

Advertisement

CRLReason Rule

Table 7-3
Description of parameters defined in the CRLNumber rule
Parameter
Description
Specifies whether the rule is enabled or disabled. Check the box to enable the rule.
enable
Uncheck the box to disable the rule (default).
• If you enable the rule and set the remaining parameters correctly, the server sets
• If you disable the rule, the server does not add the extension to CRLs; it ignores
Specifies whether the extension should be marked critical or noncritical in CRLs
critical
issued by the server. Check the box if you want the server to mark the extension
critical. Uncheck the box if you want the server to mark the extension noncritical
(default).
CRLReason Rule
The
CRLReason
ReasonCode Extension defined in X.509 and PKIX standard RFC 2459 (see
http://www.ietf.org/rfc/rfc2459.txt
to identify the reason for the revocation of a certificate included in the CRL.
For general guidelines on setting the CRL reason code in CRL entries, see
"reasonCode" on page 366.
The revocation reasons defined by the standard are listed in Table 7-4.
Table 7-4
Certificate revocation reasons
Code
Reason
0
unspecified
1
keyCompromise
2
cACompromise
3
affiliationChanged
4
superseded
5
cessationOfOperation
6
certificateHold
8
removeFromCRL
284
Netscape Certificate Management System Plug-Ins Guide • May 2002
the CRL number extension in CRLs.
the values in the remaining fields.
rule enables you to configure a Certificate Manager to set the CRL
) in CRL entries. The extension is used

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents