Defaults Reference
Chapter 11
Certificate Profiles
441
ExcludedSubtree
NameChoice_<n>
Specifies the general-name type for the excluded subtree you want to
include in the extension.
Permissible values:
RFC822Name
,
DirectoryName
,
DNSName
,
EDIPartyName
,
URIName
,
IPAddress
,
OIDName
, or
OtherName
.
ExcludedSubtrees
NameValue_<n>
Specifies the general-name value for the permitted subtree you want to
include in the extension.
•
If you selected
RFC822Name
, the value must be a valid Internet
mail address in fully-qualified DNS format. For example,
testCA@example.com
.
•
If you selected
DirectoryName
, the value must be a string form
of X.500 name, similar to the subject name in a certificate. For
example,
CN=SubCA, OU=Research Dept, O=Example
Corporation, C=US
.
•
If you selected
DNSName
, the value must be a valid domain name
in the fully-qualified DNS format. For example,
testCA.example.com
.
•
If you selected
EDIPartyName
, the value must be a IA5String.
For example,
Example Corporation
.
•
If you selected
URIName
, the value must be a non-relative
universal resource identifier (URI) following the URL syntax and
encoding rules. The name must include both a scheme (for
example,
http
) and a fully qualified domain name or IP address
of the host. For example,
http://testCA.example.com
.
•
If you selected
IPAddress
, the value must be a valid IP address
(IPv4 or IPv6).
IPv4 address must be in
n.n.n.n
format, with netmask must be
in
n.n.n.n,m.m.m.m
format. For example:
128.21.39.40
.
or
128.21.39.40,255.255.255.00
.
IPv 6 (IPv6) address with netmask is separated by a comma. FOr
Example
0:0:0:0:0:0:13.1.68.3
and
FF01::43
; and
0:0:0:0:0:0:13.1.68.3,FFFF:FFFF:FFFF:FFFF:FF
FF:FFFF:255.255.255.0
and
FF01::43,FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FF00:
0000
.
•
If you selected
OIDName
, the value must be a unique, valid OID
specified in dot-separated numeric component notation. For
example,
1.2.3.4.55.6.5.99
.
Table 11-8
Name Constraints Extension Default Configuration Parameters
(Continued)
Parameter
Description
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...