User Tools

Site Tools


nps:pki:capolicy

CAPolicy.Inf

Options for CA Policy.inf

[Version]

NameValueDescriptionRequired
Signature”$Windows NT$”Version infoYes

[certsrv_server]

NameValueDescriptionFrom Version
RenewalKeyLength512,1024,2048,4096Key Length when CA Certificate is renewed2003
RenewalValidityPerioddays,weeks,yearsValidation time for the next CA Certificate issued2003
RenewalValidityPeriodUnits(number)Validation time for the next CA Certificate issued2003
CRLPerioddays,weeks,years-2003
CRLPeriodUnits(number)-2003
CRLDeltaPerioddays,weeks,years-2003
CRLDeltaPeriodUnits(number)-2003
ClockSkewMinutes(numbers)Effective time set in CRL minus x minutes2008
LoadDefaultTemplates0/1 or True/FalseIf true, defaults templates will be loaded and automatically deployed2008
AlternateSignatureAlgorithm0/1 or True/FalseEnables PKCS #1 V2.1 Signatre format on both CA certificate and certificates issued,0=SHA384RSA,1=RSASSA-PSS(Not Supported by Cisco+++)2008
CNGHashAlgorithmSHA1,SHA256, SHA384,SHA512Hash Algorithm used to in certificates issued2008
ForceUTF80/1 or True/FalseForce relative distinguished names (RDNs) in Subject and Issuer names to be UTF-82008
EnableKeyCounting0/1 or True/FalseCA will increment a counter every time a the CA's signing key is used. (Only supported by some HSM modules, do not enable on software CSP's)2008

[BasicConstraintsExtension]

NameValueDescriptionFrom Version
PathLength(number)Number of SUBCA's. set to 0 in the LAST CA, add one for each CA above in the PKI chain2003
Critical(yes/no,1/0/true/false)2003

[CrossCertificateDistributionPointsExtension]

NameValueDescriptionFrom Version
SyncDeltaTime(number)How often in seconds the URL is updated2008
URL(URL)http location of partner CA certificate2008
Critical(yes/no,1/0/true/false)2003
nps/pki/capolicy.txt · Last modified: 2021/06/30 02:03 by vmware