Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 528

Table of Contents

Advertisement

Extension-Specific Policy Module Reference
application validating the certificate must be able to interpret the extension, or else
it must reject the certificate. Since it's unlikely that all applications will be able to
interpret your custom extensions, you should consider marking these extensions
noncritical.
Note that each instance of the policy can be configured to add one custom
extension only. To configure the server to add multiple custom extensions, create
multiple instances of the module, each with a distinct name and appropriate
configuration values. Also note that the policy allows you to encode simple
(possibly nested) SEQUENCEs. There is no support for CHOICE, SET, or ASN.1
tagging.
During installation, CMS automatically creates an instance of the generic ASN.1
extension policy, named
Configuration Parameters of GenericASN1Ext
The configuration defines a custom extension named
2.4.5.99. The extension is non-critical, and it will be added to all certificates issued
by the server. The expected
Command-Line Tools Guide) of the resulting extension, would look like this:
337 30
148: . . . . SEQUENCE {
340 06
3: . . . . . OBJECT IDENTIFIER '2 4 5 99'
345 04
140: . . . . . OCTET STRING, encapsulates {
348 30
137: . . . . . . . SEQUENCE {
351 13
24: . . . . . . . . PrintableString '1st data in 1st sequence'
377 16
24: . . . . . . . . IA5String '2nd data in 1st sequence'
403 13
32: . . . . . . . . PrintableString 'This is 3rd data in 1st
437 04
10: . . . . . . . . OCTET STRING
: . . . . . . . . . 11 22 33 44 A0 B0 C0 D0 E0 F0
449 30
37: . . . . . . . . SEQUENCE {
451 17
13: . . . . . . . . . UTCTime '000406070000Z'
466 30
8: . . . . . . . . . SEQUENCE {
468 01
1: . . . . . . . . . . BOOLEAN TRUE
471 06
3: . . . . . . . . . . OBJECT IDENTIFIER '2 4 5 100'
: . . . . . . . . . . }
476 04
10: . . . . . . . . . OCTET STRING
: . . . . . . . . . 11 22 33 44 A0 B0 C0 D0 E0 F0
: . . . . . . . . . }
: . . . . . . . . }
: . . . . . . . }
: . . . . . }
528
Netscape Certificate Management System Administrator's Guide • February 2003
, that is disabled by default.
GenericASN1Ext
output (see "dumpasn1 Tool" in CMS
dumpasn1
sequence'
with OID
testGenASN1Ext

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents