Constraints Reference
Chapter 11
Certificate Profiles
457
Signing Algorithm Constraint
The signing algorithm constraint checks if the signing algorithm in the certificate request
satisfies the criteria set in this constraint.
Table 11-22
Netscape Certificate Type
Extension Constraint Configuration Parameters
Parameter
Description
critical
Select true to allow this extension to be marked critical; select
false to keep this extension from being marked critical; select
“-”
to indicate no constraints are placed for this parameter.
SSLClient
Specifies that the certificate can be used by clients for
authentication during SSL connections. Select true to allow this
capability; select false to not allow this capability; select
“-”
to
indicate no constraints are placed for this parameter.
SSLServer
Specifies that the certificate can be used by servers for
authentication during SSL connections. Select true to allow this
capability; select false to not allow this capability; select
“-”
to
indicate no constraints are placed for this parameter.
CertEmail
Specifies that the certificate can be used to send secure email
messages. Select true to allow this capability; select false to not
allow this capability; select
“-”
to indicate no constraints are
placed for this parameter.
CertObjectSigning
Specifies that the certificate can be used for signing objects such
as Java applets and plug-ins. Select true to allow this capability;
select false to not allow this capability; select
“-”
to indicate no
constraints are placed for this parameter.
CertSSLCA
Specifies that the certificate can be used by a CA to issue
certificates for SSL connections. Select true to allow this
capability; select false to not allow this capability; select
“-”
to
indicate no constraints are placed for this parameter.
CertEmailCA
Specifies that the certificate can be used by a CA to issue
certificates for secure email. Select true to allow this capability;
select false to not allow this capability; select
“-”
to indicate no
constraints are placed for this parameter.
CertObjectSigningCA
Specifies that the certificate can be used by a CA to issue
certificates for object signing. Select true to allow this capability;
select false to not allow this capability; select
“-”
to indicate no
constraints are placed for this parameter.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...