Configuring Policy Rules For A Subsystem - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

Note that the policy processor applies only the enabled policy rules, in the order in
which they are configured, before determining the final outcome. Each rule the
processor executes returns a
possible:
PolicyResult.REJECTED
PolicyResult.DEFERRED
PolicyResult.ACCEPTED
After all the policy rules are applied, the processor determines the status of the
request (in this order):
If the request failed any policy rule (that is, if any of the policy rules returned a
1.
PolicyResult.REJECTED
that rejected the request sets appropriate error messages on the request.
If at least one of the policy rules requires agent approval for the request (that is,
2.
if any of the policy rules returned a
processor stores the request in the request queue for agent approval.
If the request passes all the policy rules (that is, all policy rules returned a
3.
PolicyResult.ACCEPTED
certificate is issued or renewed.

Configuring Policy Rules for a Subsystem

You can configure the main subsystems of Certificate Management System
(CMS)—the Certificate Manager, Registration Manager, and Data Recovery
Manager—to apply certain organizational policies on end entities' certificate
enrollment, renewal, and revocation requests before servicing them. This section
explains how to configure a subsystem to evaluate end-entity requests based on a
set of policy rules.
The steps are as follows:
Step 1. Before You Begin
Step 2. Modify Existing Policy Rules
Step 3. Delete Unwanted Policy Rules
Step 4. Add New Policy Rules
Step 5. Reorder Policy Rules
object. Three return values are
PolicyResult
(indicates that the request failed the rule)
(indicates that the request requires agent approval)
(indicates that the request passed the rule)
value), the processor rejects the request. The rule
PolicyResult.DEFERRED
value), the request gets serviced—for example the
Configuring Policy Rules for a Subsystem
value), the
Chapter 18
Setting Up Policies
569

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents