Setting Up a Mail Server
If the subsystem will be sending out email notifications, you can configure the
subsystem to use a mail server, see "Mail Server," on page 259.
Changing the Certificate Issuance Rules
You can change some of the rules about certificate issuance that were either
determined during installation, or are the system defaults. These include:
•
Whether certificates can be issued that are for validity periods longer than the
Certificate Managers CA signing certificate, the default is to not allow.
•
The serial number range the CA is able to use to issue certificates.
•
The signing algorithm used to sign certificates.
To change the certificate issuance rules:
In the CMS window, select the Configuration tab.
1.
In the navigation tree, select Certificate Manager.
2.
The General Setting tab appears.
Change the following fields in this tab:
3.
Override validity nesting requirement. Specifies if the Certificate Manager
can issue certificates with validity periods beyond that of its CA signing
certificate.
If deselected and the Certificate Manager (CA) receives a request with validity
period extending beyond that of its CA signing certificate, it automatically
truncates the validity period to end on the day the CA signing certificate
expires.
Validity periods of certificates during enrollment is determined by the
ValidityConstraints
Similarly, validity periods of certificates during renewal is determined by the
RenewalValidityConstraints
"RenewalValidityConstraints," on page 501.
Certificate Serial Number. Specifies the serial number range for certificates
issued by this Certificate Manager. The server assigns the serial number you
enter in the "Next serial number" to the next certificate it issues and the
number you enter in the "Ending serial number" to the last certificate it issues.
plug-in module, "ValidityConstraints," on page 508.
plug-in module, see
Configuring the Certificate Manager
Chapter 3
Certificate Manager
117
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR and is the answer not in the manual?