Crl Distribution Points Extension Default - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Defaults Reference

CRL Distribution Points Extension Default

This default populates the CRL Distribution points extension in the certificate
request. This extension, when present in a certificate, identifies one or more
locations from which an application that is validating the certificate can obtain the
CRL information (to verify the revocation status of the certificate).
For general information about this extension, see "CRLDistributionPoints" on
page 726.
You can define the following constraints with this default:
Extension Constraint, see "Extension Constraint," on page 475
No Constraints, see "No Constraint," on page 477
This default allows you to define 5 locations and specify parameters for each
location. The parameters are marked with an
parameter is associated with one of the five possible locations.
Table 10-3 CRL Distribution Points Extension Configuration Parameters
Parameter
Critical
Type_<n>
Name_<n>
452
Netscape Certificate Management System Administrator's Guide • February 2003
in the table to distinguish that the
<n>
Description
Select true to mark this extension critical; select false to
mark the extension noncritical.
Specifies the type of the CRL distribution point.
Permissible values: DirectoryName, URIName, or
RelativeToIssuer. The type you select must
correspond to the value in the Name field.
Specifies the name of the CRL distribution point, the
name can be in any of the following formats:
• An X.500 directory name in the RFC 2253 syntax. For
example, the name would look similar to the subject
name in a certificate, like this: CN=CA Central,
OU=Research Dept, O=Example Corporation,
C=US
• A URIName; for example, it would look similar to
this:
http://testCA.example.com:80
• An RDN which specifies a location relative to the CRL
Issuer. In this case, the value of the Type attribute
must be RelativeToIssuer.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents