Issuerconstraints - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Table 11-4 DSAKeyConstraints Configuration Parameters (Continued)
Parameter
Description
Specifies the minimum length, in bits, for the key (the length of the modulus in bits).
minSize
The value must be smaller than or equal to the one specified by the maxSize
parameter. Permissible values: 512 or 1024. You may also enter a custom key size
that is between 512 and 1024, in increments of 64 bits. The default value is 512.
Specifies the maximum length, in bits, for the key. Permissible values: 512 or 1024.
maxSize
You may also enter a custom key size that is between 512 and 1024, in increments of
64 bits. The default value is 1024.
Limits the possible public exponent values. Use commas to separate different values.
exponents
Some exponents are more widely used than others. The following exponent values
are recommended for arithmetic and security reasons: 17 and 65537. Of these two
values, 65537 is preferred. (This setting is mainly an issue if you are using your own
software for generating key pairs. Key-generation programs in Netscape clients and
servers use 3 or 65537.)
Permissible values: A combination of 3, 7, 17, and 65537, separated by commas. The
default value is 3,7,17,65537.

IssuerConstraints

The
IssuerConstraints
certificate-based enrollment explained in "Certificate-Based Enrollment" on
page 409.
The policy enables the Certificate Manager to authenticate an end user by checking
the issuer DN of the CA that has issued the certificate the user presents as an
enrollment token during enrollment. Note that in the current implementation, the
CA that issues the new certificates must be the same as the one that has issued the
certificates used for SSL client authentication; that is, the issuer DN in the
authentication certificate must match the issuer DN specified in the policy
configuration.
During installation, CMS automatically creates an instance of the issuer constraints
policy, named
Table 11-5 describes the configuration parameters of the
policy.
plug-in module enables you to effectively deploy
, that is disabled by default.
IssuerRule
Constraints-Specific Policy Module Reference
IssuerConstraints
Chapter 11
Policies
499

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents