Configuring Policy Rules for a Subsystem
574
Netscape Certificate Management System Installation and Setup Guide • May 2002
Step 3. Delete Unwanted Policy Rules
You can delete any unwanted policy rules from the CMS configuration. If you
think you might need a rule in the future, instead of deleting it from the
configuration you should disable it by unchecking the
enable
parameter. In this
way, you can avoid re-creating the rule in the future. Because the subsystems
subject end-entity requests only to rules that are currently enabled (see “Policy
Processor” on page 568), keeping unwanted rules in the disabled state in the
configuration does not affect policy decisions made by a subsystem.
To delete a policy rule from the CMS configuration:
1.
In the Policy Rules Management tab, select the rule you want to delete and
click Delete.
2.
When prompted, confirm the delete action.
The CMS configuration is modified. If the changes you made require you to
restart the server, you will be prompted accordingly. Don’t restart the server
yet; you can do so after you’ve made all the required changes.
Step 4. Add New Policy Rules
Adding a policy rule to the CMS configuration involves creating a new instance of
an already registered policy plug-in module, assigning a unique name for the
instance, and entering appropriate values for the parameters that define the
module you want to create an instance of.
When you add a policy rule, the CMS configuration gets updated with
policy-specific information. Keep the following points in mind:
•
When naming a policy instance (or rule), be sure to formulate the name using
any combination of letters (aA to zZ), digits (0 to 9), an underscore (_), and a
hyphen (-); other characters and spaces are not allowed. For example, you can
type
My_Policy_Rule
or
MyPolicyRule
as the instance name, but not
My
Policy Rule
.
•
The status of the rule, enabled or disabled, depends on whether you check or
uncheck the
enable
parameter. A subsystem subjects certificate requests only
to rules that are enabled.
•
The server does not automatically reorder rules. Be sure to change the order of
the rule, if required.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...