Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual page 58

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

System Overview
Policy plug-in modules for checking and formulating certificate contents (Continued)
Table 1-3
Plug-in module name
KeyAlgorithmConstraints
RenewalConstraints
RenewalValidityConstraints
RevocationConstraints
RSAKeyConstraints
SigningAlgorithmConstraints
SubCANameConstraints
UniqueSubjectNameConstraints
ValidityConstraints
Certificate Management System supports the following policy modules out of the
box for formulating certificate extensions. They can be used with either a
Certificate Manager or a Registration Manager.
Table 1-4
Policy plug-in modules for setting extensions in certificates
Plug-in module name
AuthInfoAccessExt
AuthorityKeyIdentifierExt
58
Netscape Certificate Management System Installation and Setup Guide • March 2002
Description
Allows the server to certify only those keys that are generated using one
of the specified algorithms, such as RSA or DSA.
Allows or rejects requests for renewal of expired certificates.
Enforces the number of days before which a currently active certificate
can be renewed and a new validity period for the renewed certificate.
Allows or rejects requests for revocation of expired certificates.
Allows the server to certify only RSA keys of specified lengths.
Allows the server to specify the signature algorithm to be used by the
CA (a Certificate Manager) to sign certificates.
Allows the server to check for issuer name uniqueness and prevents
issuance of multiple subordinate CA certificates with same issuer
names.
Allows the server to check for certificate subject name uniqueness and
prevents issuance of multiple certificates with same subject names.
Causes the server to check whether the validity period of a certificate
falls within a specified period.
Description
Adds the Authority Information Access extension to certificates. The
extension specifies how the application validating the certificate can
access information, such as on-line validation services and CA policy
statements, about the CA that has issued the certificate in which the
extension appears.
Adds the Authority Key Identifier extension to certificates of a specified
type. The Authority Key Identifier extension identifies the public key
corresponding to the private key used to sign a certificate. This extension
is useful when an issuer has multiple signing keys (for example, due to
CA certificate renewal).

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents