Keyalgorithmconstraints - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Constraints-Specific Policy Module Reference
Table 11-5 IssuerConstraints Configuration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
enable
disable.
Specifies the predicate expression for this rule. If you want this rule to be applied to
predicate
all certificate requests, leave the field blank (default). To form a predicate expression,
see "Using Predicates in Policy Rules" on page 485.
Specifies the name of the CA that has issued certificates that are to be checked. You
issuerDN
should enter the issuer name as it appears in the CA's signing certificate; the same
name also appears as the issuer name in certificates the CA signs.
Example: CN=bulkGenCA,OU=Information Systems,O=Example
Corporation,C=US

KeyAlgorithmConstraints

The
KeyAlgorithmConstraints
requested in certificates to the algorithms, such as RSA and DSA, supported by
CMS. In other words, this policy allows you to set restrictions on the types of
public keys certified by CMS.
You may apply this policy to end-entity certificate enrollment and renewal
requests. For example, if you want your CA to certify only those public keys that
comply with the PKCS-1 RSA Encryption Standard, you can configure the server
for that using the policy.
During installation, CMS automatically creates an instance of the key algorithm
constraints policy, named
Table 11-6 describes the configuration parameters of the
KeyAlgorithmConstraints
Table 11-6 KeyAlgorithmConstraints Configuration Parameters
Parameter
Description
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
enable
disable.
Specifies the predicate expression for this rule. If you want this rule to be applied to
predicate
all certificate requests, leave the field blank (default). To form a predicate expression,
see "Using Predicates in Policy Rules" on page 485.
500
Netscape Certificate Management System Administrator's Guide • February 2003
plug-in module restricts the key algorithm
, that is enabled by default.
KeyAlgRule
policy.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents