System Overview
58
Netscape Certificate Management System Installation and Setup Guide • March 2002
Certificate Management System supports the following policy modules out of the
box for formulating certificate extensions. They can be used with either a
Certificate Manager or a Registration Manager.
KeyAlgorithmConstraints
Allows the server to certify only those keys that are generated using one
of the specified algorithms, such as RSA or DSA.
RenewalConstraints
Allows or rejects requests for renewal of expired certificates.
RenewalValidityConstraints
Enforces the number of days before which a currently active certificate
can be renewed and a new validity period for the renewed certificate.
RevocationConstraints
Allows or rejects requests for revocation of expired certificates.
RSAKeyConstraints
Allows the server to certify only RSA keys of specified lengths.
SigningAlgorithmConstraints
Allows the server to specify the signature algorithm to be used by the
CA (a Certificate Manager) to sign certificates.
SubCANameConstraints
Allows the server to check for issuer name uniqueness and prevents
issuance of multiple subordinate CA certificates with same issuer
names.
UniqueSubjectNameConstraints
Allows the server to check for certificate subject name uniqueness and
prevents issuance of multiple certificates with same subject names.
ValidityConstraints
Causes the server to check whether the validity period of a certificate
falls within a specified period.
Table 1-4
Policy plug-in modules for setting extensions in certificates
Plug-in module name
Description
AuthInfoAccessExt
Adds the Authority Information Access extension to certificates. The
extension specifies how the application validating the certificate can
access information, such as on-line validation services and CA policy
statements, about the CA that has issued the certificate in which the
extension appears.
AuthorityKeyIdentifierExt
Adds the Authority Key Identifier extension to certificates of a specified
type. The Authority Key Identifier extension identifies the public key
corresponding to the private key used to sign a certificate. This extension
is useful when an issuer has multiple signing keys (for example, due to
CA certificate renewal).
Table 1-3
Policy plug-in modules for checking and formulating certificate contents (Continued)
Plug-in module name
Description
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...