No Constraint
455
Parameter
Description
false
to keep this from being set; select a
hyphen,
-
, to indicate no constraints are placed
for this parameter.
decipherOnly
Specifies whether to set the extension if the
public key is to be used only for deciphering
data. If this bit is set,
keyAgreement
should
also be set. Select
true
to allow this to be set;
select
false
to keep this from being set; select
a hyphen,
-
, to indicate no constraints are placed
for this parameter.
Table B.23. Key Usage Extension Constraint Configuration Parameters
B.2.6. No Constraint
This constraint implements no constraint. When chosen along with a default, there are not constraints
placed on that default.
B.2.7. Netscape Certificate Type Extension Constraint
WARNING
This constraint is obsolete. Instead of using the Netscape Certificate Type extension
constraint, use the Key Usage extension or Extended Key Usage extension.
The Netscape Certificate Type extension constraint checks if the Netscape Certificate Type extension
in the certificate request satisfies the criteria set in this constraint.
B.2.8. Renewal Grace Period Constraint
The Renewal Grace Period Constraint sets rules on when a user can renew a certificate based on its
expiration date. For example, users cannot renew a certificate until a certain time before it expires or if
it goes past a certain time after its expiration date.
One important thing to remember when using this constraint is that this constraint is set on the
original
enrollment profile
, not the renewal profile. The rules for the renewal grace period are part of the
original certificate and are carried over and applied for any subsequent renewals.
This constraint is only available with the No Default extension.
Parameter
Description
renewal.graceAfter
Sets the period, in days,
after
the certificate
expires that it can be submitted for renewal. If the
certificate has been expired longer that that time,
then the renewal request is rejected.
renewal.graceBefore
Sets the period, in days,
before
the certificate
expires that it can be submitted for renewal. If the
certificate is not that close to its expiration date,
then the renewal request is rejected.
Table B.24. Renewal Grace Period Constraint Configuration Parameters
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...