Sophie

Sophie

distrib > Mandriva > 2010.2 > i586 > by-pkgid > 0c89b3ea2a5834ec2b3bc40317678ccb > files > 9

xca-0.9.1-1mdv2010.2.i586.rpm

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<HTML>
<HEAD>
 <META NAME="GENERATOR" CONTENT="LinuxDoc-Tools 0.9.21">
 <TITLE>XCA - X Certificate and key management: Options</TITLE>
 <LINK HREF="xca-13.html" REL=next>
 <LINK HREF="xca-11.html" REL=previous>
 <LINK HREF="xca.html#toc12" REL=contents>
</HEAD>
<BODY>
<A HREF="xca-13.html">Next</A>
<A HREF="xca-11.html">Previous</A>
<A HREF="xca.html#toc12">Contents</A>
<HR>
<H2><A NAME="s12">12.</A> <A HREF="xca.html#toc12">Options</A></H2>


<P>The options dialog can be found in the file menu. All options are saved
in the database and do not depend on the operating systems registry or
configuration files.</P>



<H2><A NAME="ss12.1">12.1</A> <A HREF="xca.html#toc12.1">Mandatory subject entries</A>
</H2>


<P>A list of mandatory distinguished name entries may be specified to
get a warning, whenever issuing a certificate that lacks one or more listed
entries. This requirement is not checked when editing templates,
because templates may have empty entries that will be filled during
the rollout of the certificate.</P>



<H2><A NAME="ss12.2">12.2</A> <A HREF="xca.html#toc12.2">String settings</A>
</H2>


<P>This option applies to all strings converted to ASN1 strings.
The selected string type is automatically set to
the smallest possible and allowed type, covering all contained characters.</P>


<P>The list of allowed string types can be selected:</P>
<P>
<UL>
<LI><B>PKIX in RFC2459 (default)</B>All string types are
set as described in RFC2459</LI>
<LI><B>No BMP strings</B> All strings containing non printable
characters are regarded as errors.</LI>
<LI><B>PKIX UTF8 only</B> All string types are selected according to
RFC2459 for entities issued after 2004, which means that almost all
distinguished name entry types are set to UTF8.</LI>
<LI><B>All strings</B>All string types are allowed.</LI>
</UL>
</P>



<H2><A NAME="ss12.3">12.3</A> <A HREF="xca.html#toc12.3">Default hash algorithm</A>
</H2>


<P>Older Windows versions and OpenSSL versions can not handle
SHA256 and SHA512. This option allows to set the hash algorithm to SHA1
for instance.</P>



<H2><A NAME="ss12.4">12.4</A> <A HREF="xca.html#toc12.4">PKCS#11 library path</A>
</H2>


<P>Here you can select the path to the PKCS#11 library on your system.
If it is empty, the default <CODE>/usr/lib/opensc-pkcs11.so</CODE> will be used.
On Windows the opensc-pkcs11.dll in the XCA installation directory will be tried.</P>

<HR>
<A HREF="xca-13.html">Next</A>
<A HREF="xca-11.html">Previous</A>
<A HREF="xca.html#toc12">Contents</A>
</BODY>
</HTML>