Class PolicyConstraintsExt

  • All Implemented Interfaces:
    IExtendedPluginInfo, com.netscape.certsrv.request.IPolicy, org.dogtagpki.legacy.policy.IEnrollmentPolicy, org.dogtagpki.legacy.policy.IPolicyRule

    public class PolicyConstraintsExt
    extends APolicyRule
    implements org.dogtagpki.legacy.policy.IEnrollmentPolicy, IExtendedPluginInfo
    Policy Constraints Extension Policy Adds the policy constraints extension to (CA) certificates. Filtering of CA certificates is done through predicates.

     NOTE:  The Policy Framework has been replaced by the Profile Framework.
     

    Version:
    $Revision$, $Date$
    • Field Detail

      • logger

        public static org.slf4j.Logger logger
      • PROP_REQ_EXPLICIT_POLICY

        protected static final java.lang.String PROP_REQ_EXPLICIT_POLICY
        See Also:
        Constant Field Values
      • PROP_INHIBIT_POLICY_MAPPING

        protected static final java.lang.String PROP_INHIBIT_POLICY_MAPPING
        See Also:
        Constant Field Values
      • DEF_REQ_EXPLICIT_POLICY

        protected static final int DEF_REQ_EXPLICIT_POLICY
        See Also:
        Constant Field Values
      • DEF_INHIBIT_POLICY_MAPPING

        protected static final int DEF_INHIBIT_POLICY_MAPPING
        See Also:
        Constant Field Values
      • mEnabled

        protected boolean mEnabled
      • mCritical

        protected boolean mCritical
      • mReqExplicitPolicy

        protected int mReqExplicitPolicy
      • mInhibitPolicyMapping

        protected int mInhibitPolicyMapping
      • mPolicyConstraintsExtension

        protected org.mozilla.jss.netscape.security.x509.PolicyConstraintsExtension mPolicyConstraintsExtension
      • mInstanceParams

        protected java.util.Vector<java.lang.String> mInstanceParams
      • mDefaultParams

        protected static java.util.Vector<java.lang.String> mDefaultParams
    • Constructor Detail

      • PolicyConstraintsExt

        public PolicyConstraintsExt()
    • Method Detail

      • init

        public void init​(org.dogtagpki.legacy.policy.IPolicyProcessor owner,
                         IConfigStore config)
                  throws EBaseException
        Initializes this policy rule.

        The entries may be of the form: ca.Policy.rule..predicate=certType==ca ca.Policy.rule..implName= ca.Policy.rule..enable=true

        Specified by:
        init in interface org.dogtagpki.legacy.policy.IPolicyRule
        Specified by:
        init in class APolicyRule
        Parameters:
        config - The config store reference
        Throws:
        EBaseException
      • apply

        public com.netscape.certsrv.request.PolicyResult apply​(com.netscape.certsrv.request.IRequest req)
        Adds Policy Constraints Extension to a (CA) certificate. If a Policy constraints Extension is already there, accept it if it's been approved by agent, else replace it.
        Specified by:
        apply in interface com.netscape.certsrv.request.IPolicy
        Specified by:
        apply in interface org.dogtagpki.legacy.policy.IPolicyRule
        Specified by:
        apply in class APolicyRule
        Parameters:
        req - The request on which to apply policy.
        Returns:
        The policy result object.
      • applyCert

        public com.netscape.certsrv.request.PolicyResult applyCert​(com.netscape.certsrv.request.IRequest req,
                                                                   org.mozilla.jss.netscape.security.x509.X509CertInfo certInfo)
      • getInstanceParams

        public java.util.Vector<java.lang.String> getInstanceParams()
        Return configured parameters for a policy rule instance.
        Specified by:
        getInstanceParams in interface org.dogtagpki.legacy.policy.IPolicyRule
        Specified by:
        getInstanceParams in class APolicyRule
        Returns:
        nvPairs A Vector of name/value pairs.
      • getDefaultParams

        public java.util.Vector<java.lang.String> getDefaultParams()
        Return default parameters for a policy implementation.
        Specified by:
        getDefaultParams in interface org.dogtagpki.legacy.policy.IPolicyRule
        Specified by:
        getDefaultParams in class APolicyRule
        Returns:
        nvPairs A Vector of name/value pairs.
      • getExtendedPluginInfo

        public java.lang.String[] getExtendedPluginInfo​(java.util.Locale locale)
        gets plugin info for pretty console edit displays.
        Specified by:
        getExtendedPluginInfo in interface IExtendedPluginInfo