Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 468

Table of Contents

Advertisement

Defaults Reference
In general, you can configure which attributes should or shouldn't be stored in the
request; for example, you can exclude sensitive attributes such as passwords from
getting stored in the request with the help of the parameter named
dontSaveHttpParams
this parameter, see the description for
All Interfaces" of CMS Customization Guide. You can also distinguish the attributes
based on their origin—that is, whether they originated from the enrollment form or
where added to the request during the authentication process. Authenticated
attributes have
non-authenticated attributes such as the ones that come from the HTTP input have
HTTP_PARAMS
If enabled, the subject alternative extension policy checks the certificate request for
configured attributes. If the request contains an attribute, the policy reads its value
and sets it in the extension. This way, the extension that gets to added to certificates
contains all the configured attributes.
You can define the following constraints with this default:
Extension Constraint, see "Extension Constraint," on page 475.
No Constraints, see "No Constraint," on page 477.
Table 10-15 Subject Alternative Name Extension Default Configuration Parameters
Parameter
Critical
Pattern
468
Netscape Certificate Management System Administrator's Guide • February 2003
defined in the CMS configuration file. For details on using
as prefix (for example,
AUTH_TOKEN
as prefix (for example,
Description
Select true to mark this extension critical; select false to mark the extension
noncritical.
Specifies the request attribute whose value is to be included in the
extension. The attribute value must conform to any of the supported
general-name types. If the server finds the attribute in the request, it sets
the attribute value in the extension and then adds the extension to
certificates. If you specify multiple attributes and if none of the attributes
are present in the request, the server does not add the subject alternative
name extension to certificates.
Permissible values: A request attribute included in the certificate request.
Example: $request.requestor_email$
in section "JavaScript Used By
HTTP_PARAMS
AUTH_TOKEN.mail
HTTP_PARAMS.csrRequestorEmail
) and
).

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents