Nameconstraintsext - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Table 11-28 KeyUsageExt Configuration Parameters (Continued)
Parameter
decipherOnly

NameConstraintsExt

The
Extension to certificates. The extension is used in CA certificates to indicate a name
space within which subject names or subject alternative names in subsequent
certificates in a certification path or chain should be located.
For general information about this extension, see "nameConstraints" on page 730.
During installation, CMS automatically creates an instance of the name constraints
extension policy, named
Table 11-29 NameConstraintsExt Configuration Parameters
Parameter
enable
predicate
critical
Description
Specifies whether to set the decipherOnly bit (or bit 8) of the key usage extension
in certificates specified by the predicate parameter.
Permissible values: true, false, or HTTP_INPUT.
• Select true if you want the server to set the bit (default).
• Select false if you don't want the server to set the bit.
• Select HTTP_INPUT if you want the server to check the certificate request for
the HTTP input variable corresponding to the decipherOnly bit and set the
bit accordingly. If the variable is set to true, the server sets the bit. If the
variable doesn't exist or if it is set to false (or any other value), the server
doesn't set the bit.
NameConstraintsExt
NameConstraintsExt
Description
Specifies whether the rule is enabled or disabled. Select to enable, deselect
to disable.
Specifies the predicate expression for this rule. If you want this rule to be
applied to all certificate requests, leave the field blank (default). To form a
predicate expression, see section "Using Predicates in Policy Rules" in
Chapter 18, "Setting Up Policies" of CMS Administrator's Guide.
Example: HTTP_PARAMS.certType==ca
Specifies whether the extension should be marked critical or noncritical.
Select to mark critical (default), deselect to mark noncritical.
plug-in module enables you to add the Name Constraints
, that is disabled by default.
Extension-Specific Policy Module Reference
Chapter 11
Policies
541

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents