Index     Next     
iPlanet Certificate Management System Plug-ins Guide



Contents


About This Guide
What's in This Guide
What You Should Already Know
Conventions Used in This Guide
Where to Go for Related Information


Chapter 1 Authentication Plug-in Modules
Overview of Authentication Modules
Manual Authentication
UidPwdDirAuth Plug-in Module
Configuration Parameters of UidPwdDirAuth
UidPwdPinDirAuth Plug-in Module
Configuration Parameters of UidPwdPinDirAuth
NISAuth Plug-in Module
Configuration Parameters of NISAuth
PortalEnroll Plug-in Module
Configuration Parameters of PortalAuth
Certificate-Based Enrollment
Enrollment Forms
Customizing Enrollment Forms for Generating DSA Key Pairs
Generating Files Required By Third-Party Object Signing Tools


Chapter 2 Job Plug-in Modules
Overview of Job Plug-in Modules
RenewalNotificationJob Plug-in Module
Configuration Parameters of RenewalNotificationJob
RequestInQJob Plug-in Module
Configuration Parameters of RequestInQJob
UnpublishExpiredJob Plug-in Module
Configuration Parameters of UnpublishExpiredJob
Schedule for Executing Jobs
Customizing Notification Messages
Templates for Summary Notifications
Customizing Message Templates
Tokens Available in Message Templates
Tokens for Renewal Notification Messages
Tokens for Request In Queue Notification Messages
Tokens for Directory Update Notification Messages


Chapter 3 Constraints Policy Plug-in Modules
Overview of Constraints-Specific Policy Modules
AttributePresentConstraints Plug-in Module
Configuration Parameters of AttributePresentConstraints
DSAKeyConstraints Plug-in Module
Configuration Parameters of DSAKeyConstraints
DSAKeyRule Rule
IssuerConstraints Plug-in Module
Configuration Parameters of IssuerConstraints
IssuerRule Rule
KeyAlgorithmConstraints Plug-in Module
Configuration Parameters of KeyAlgorithmConstraints
KeyAlgRule Rule
RenewalConstraints Plug-in Module
Configuration Parameters of RenewalConstraints
RenewalConstraintsRule Rule
RenewalValidityConstraints Plug-in Module
Configuration Parameters of RenewalValidityConstraints
DefaultRenewalValidityRule Rule
RevocationConstraints Plug-in Module
Configuration Parameters of RevocationConstraints
RevocationConstraintsRule Rule
RSAKeyConstraints Plug-in Module
Configuration Parameters of RSAKeyConstraints
RSAKeyRule Rule
SigningAlgorithmConstraints Plug-in Module
Configuration Parameters of SigningAlgorithmConstraints
SigningAlgRule Rule
SubCANameConstraints Plug-in Module
Configuration Parameters of SubCANameConstraints
SubCANameConstraints Rule
UniqueSubjectNameConstraints Plug-in Module
Configuration Parameters of UniqueSubjectNameConstraints
UniqueSubjectNameConstraints Rule
ValidityConstraints Plug-in Module
Configuration Parameters of ValidityConstraints
DefaultValidityRule Rule


Chapter 4 Certificate Extension Plug-in Modules
Overview of Extension-Specific Policy Modules
AuthInfoAccessExt Plug-in Module
Configuration Parameters of AuthInfoAccessExt
AuthInfoAccessExt Rule
AuthorityKeyIdentifierExt Plug-in Module
Configuration Parameters of AuthorityKeyIdentifierExt
AuthorityKeyIdentifierExt Rule
BasicConstraintsExt Plug-in Module
Configuration Parameters of BasicConstraintsExt
BasicConstraintsExt Rule
CertificatePoliciesExt Plug-in Module
Configuration Parameters of CertificatePoliciesExt
CertificatePoliciesExt Rule
CertificateRenewalWindowExt Plug-in Module
Configuration Parameters of CertificateRenewalWindowExt
CertificateScopeOfUseExt Plug-in Module
Configuration Parameters of CertificateScopeOfUseExt
CRLDistributionPointsExt Plug-in Module
Configuration Parameters of CRLDistributionPointsExt
CRLDistributionPointsExt Rule
ExtendedKeyUsageExt Plug-in Module
Configuration Parameters of ExtendedKeyUsageExt
CODESigningExt Rule
OCSPSigningExt Rule
GenericASN1Ext Plug-in Module
Configuration Parameters of GenericASN1Ext
GenericASN1Ext Rule
IssuerAltNameExt Plug-in Module
Configuration Parameters of IssuerAltNameExt
KeyUsageExt Plug-in Module
Configuration Parameters of KeyUsageExt
CMCertKeyUsageExt Rule
RMCertKeyUsageExt Rule
ServerCertKeyUsageExt Rule
ClientCertKeyUsageExt Rule
ObjSignCertKeyUsageExt Rule
CRLSignCertKeyUsageExt
NameConstraintsExt Plug-in Module
Configuration Parameters of NameConstraintsExt
NameConstraintsExt Rule
NSCCommentExt Plug-in Module
Configuration Parameters of NSCCommentExt
NSCCommentExt Rule
NSCertTypeExt Plug-in Module
Configuration Parameters of NSCertTypeExt
NSCertTypeExt Rule
OCSPNoCheckExt Plug-in Module
Configuration Parameters of OCSPNoCheckExt
OCSPNoCheckExt Rule
PolicyConstraintsExt Plug-in Module
Configuration Parameters of PolicyConstraintsExt
PolicyConstraintsExt Rule
PolicyMappingsExt Plug-in Module
Configuration Parameters of PolicyMappingsExt
PolicyMappingsExt Rule
PrivateKeyUsagePeriodExt Plug-in Module
Configuration Parameters of PrivateKeyUsagePeriodExt
RemoveBasicConstraintsExt Plug-in Module
Configuration Parameters of RemoveBasicConstraintsExt
SubjectAltNameExt Plug-in Module
Configuration Parameters of SubjectAltNameExt
SubjectAltNameExt Rule
SubjectDirectoryAttributesExt Plug-in Module
Configuration Parameters of SubjectDirectoryAttributesExt
SubjectKeyIdentifierExt Plug-in Module
Configuration Parameters of SubjectKeyIdentifierExt
SubjectKeyIdentifierExt Rule


Chapter 5 Mapper Plug-in Modules
Overview of Mapper Modules
LdapCaSimpleMap Plug-in Module
Configuration Parameters of LdapCaSimpleMap
LdapCaCertMap Mapper
LdapCrlMap Mapper
LdapDNCompsMap Plug-in Module
Configuration Parameters of LdapDNCompsMap
LdapDNExactMap Plug-in Module
Configuration Parameters of LdapDNExactMap
LdapSimpleMap Plug-in Module
Configuration Parameters of LdapSimpleMap
LdapUserCertMap Mapper
LdapSubjAttrMap Plug-in Module
Configuration Parameters of LdapSubjAttrMap


Chapter 6 Publisher Plug-in Modules
Overview of Publisher Modules
FileBasedPublisher Plug-in Module
Configuration Parameters of FileBasedPublisher
LdapCaCertPublisher Plug-in Module
Configuration Parameters of LdapCaCertPublisher
LdapCaCertPublisher Publisher
LdapUserCertPublisher Plug-in Module
Configuration Parameters of LdapUserCertPublisher
LdapUserCertPublisher Publisher
LdapCrlPublisher Plug-in Module
Configuration Parameters of LdapCrlPublisher
LdapCrlPublisher Publisher
OCSPPublisher Plug-in Module
Configuration Parameters of OCSPPublisher


Chapter 7 CRL Extension Plug-in Modules
Overview of CRL Extension Modules
AuthorityKeyIdentifier Rule
CRLNumber Rule
CRLReason Rule
HoldInstruction Rule
InvalidityDate Rule
IssuerAlternativeName Rule
IssuingDistributionPoint Rule


Chapter 8 Log Plug-in Modules
Overview of Log Modules
file Plug-in Module
Configuration Parameters of file
Audit Log Event Listener
Error Log Event Listener
System Log Event Listener
NTEventLog Plug-in Module
Configuration Parameters of NTEventLog
NTAudit Event Listener
NTSystem Event Listener


Appendix A Distinguished Names
What Is a Distinguished Name?
Distinguished Name Components
Root Distinguished Name
Base Distinguished Name
DNs in Certificate Management System
Extending Attribute Support
Adding New or Proprietary Attributes
Adding Attributes to an Enrollment Form
Changing the DER Encoding Order
Role of Distinguished Names in Certificates
DNs in End-Entity Certificates
DNs in CA Certificates
Selecting DNs for Certificates
DN Patterns and Certificate Subject Names


Appendix B Object Identifiers
What's an Object Identifier?
Registration of Object Identifiers


Appendix C Certificate and CRL Extensions
Introduction to Certificate Extensions
Structure of Certificate Extensions
Sample Certificate Extensions
Recommendations for Certificate Extension Use
Standard X.509 v3 Certificate Extensions
authorityInfoAccess
authorityKeyIdentifier
basicConstraints
certificatePolicies
cRLDistributionPoints
extKeyUsage
issuerAltName
keyUsage
nameConstraints
OCSPNocheck
policyConstraints
policyMappings
privateKeyUsagePeriod
subjectAltName
subjectDirectoryAttributes
subjectKeyIdentifier
Introduction to CRL Extensions
Structure of CRL Extensions
Sample CRL and CRL Entry Extensions
Standard X.509 v3 CRL Extensions
Extensions for CRLs
authorityKeyIdentifier
CRLNumber
deltaCRLIndicator
issuerAltName
issuingDistributionPoint
CRL Entry Extensions
certificateIssuer
holdInstructionCode
invalidityDate
reasonCode
Netscape-Defined Certificate Extensions
netscape-cert-type
netscape-comment
CA Certificates and Extension Interactions
Index


Index     Next     
Copyright © 2001 Sun Microsystems, Inc. Some preexisting portions Copyright © 2001 Netscape Communications Corp. All rights reserved.

Last Updated April 02, 2001