Issuingdistributionpoint - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

CRL Extension Reference
Table 14-8 IssuerAlternativeName Configuration Parameters (Continued)
Parameter

IssuingDistributionPoint

The
IssuingDistributionPoint
Manager to set the Issuing Distribution Point Extension in CRLs. The CRL issuing
point extension enables you to specify a pointer to a particular CRL and to include
additional information about the CRL at that location—whether it covers
revocation of end-entity certificates only, CA certificates only, or revoked
certificates that have a limited set of reason codes.
Optionally, each issuing point may contain a set of reason flags, indicating what
revocation reasons are covered by the CRL at the specified location. Note that you
can modify the rule to support any name form by making the appropriate changes
to the sample code provided for this purpose, see the CMS SDK.
For general guidelines on setting the issuing distribution point extension in CRLs,
see "issuingDistributionPoint" on page 773.
612
Netscape Certificate Management System Administrator's Guide • June 2003
Description
• If the type is URL, the value must be a non-relative universal
resource identifier (URI). For example:
http://testCA.example.com.
• If the type is iPAddress, the value must be a valid IP address
specified in dot-separated numeric component notation. It can be the
IP address or the IP address including the netmask.
• If the type is OID, the value must be a unique, valid OID specified in
the dot-separated numeric component notation. Although you can
invent your own OIDs for the purposes of evaluating and testing this
server, in a production environment, you should comply with the
ISO rules for defining OIDs and for registering subtrees of IDs. See
Appendix H, "Object Identifiers" for information on allocating
private OIDs. For example, 1.2.3.4.55.6.5.99.
• If the type is otherName, the name must be must be the absolute
path to the file that contains the general name in its base-64 encoded
format. For example,
/usr/netscape/servers/extn/ian/othername.txt.
rule enables you to configure a Certificate

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents