为Dogtag证书配置文件设置notBefore/notAfter及XML请求技术问询
Hey Chris, great question—let me break this down for you step by step since I’ve tinkered with Dogtag’s profile configuration quite a bit.
1. Correct ClassID for User-Configurable Validity
If you want to let requesters specify a custom validity period during enrollment, the exact ClassID you need is com.netscape.cms.profile.def.ValidityInput.
A quick note: There’s a related class com.netscape.cms.profile.def.ValidityDefault that sets a fixed default validity with no user input, but since you asked for an input field, ValidityInput is the right pick.
2. Overview Resources (No External Links Needed)
Dogtag’s best built-in resources for this are:
- Default profile files in
/var/lib/pki/pki-tomcat/ca/profiles/ca(likecaUserCert.cfgorcaServerCert.cfg). Look for sections using validity classes to see real-world examples of how they’re configured. - The Dogtag source code’s profile definition classes (if you’re comfortable digging into code) to understand the inner workings of these classes.
3. XML Request Configuration
To add the validity input field to your profile, you’ll need to update two key sections of the profile XML: the input phase (to collect the user’s value) and the policy phase (to enforce that value on the certificate). Here’s a concrete example that fits most user certificate profiles:
<Profile> <!-- ... existing profile sections (authentication, etc.) ... --> <input> <class id="ValidityInput" name="Validity Period Input" classId="com.netscape.cms.profile.def.ValidityInput"> <property name="defaultValidity" value="365"/> <!-- Default days if user doesn't specify --> <property name="minValidity" value="1"/> <!-- Minimum allowed validity in days --> <property name="maxValidity" value="1095"/> <!-- Maximum allowed validity (3 years) --> <property name="unit" value="days"/> <!-- Supported units: hours, weeks, months, years --> <property name="label" value="Certificate Validity (days)"/> <!-- Label shown in enrollment UI --> <property name="description" value="Enter the number of days the certificate should be valid (1-1095)"/> </class> <!-- ... other input classes (e.g., SubjectNameInput) ... --> </input> <policy> <class id="ValidityPolicy" name="Validity Policy" classId="com.netscape.cms.profile.def.ValidityPolicy"> <property name="allowValidityOverride" value="true"/> <!-- *Critical*: Lets user input override CA defaults --> </class> <!-- ... other policy classes ... --> </policy> <!-- ... rest of profile configuration ... --> </Profile>
Key Configuration Notes
- Don’t skip the
ValidityPolicyin the policy section—this is what actually applies the user’s input to the certificate. - Ensure
allowValidityOverrideis set totrue; without this, the CA will ignore the user’s input and use its default validity period. - Adjust
minValidity,maxValidity, andunitto match your organization’s security requirements.
If you’re using Dogtag’s text-based .cfg profile files instead of XML, the equivalent configuration would look like this:
# Input section input.classes=ValidityInput,... input.ValidityInput.classId=com.netscape.cms.profile.def.ValidityInput input.ValidityInput.defaultValidity=365 input.ValidityInput.minValidity=1 input.ValidityInput.maxValidity=1095 input.ValidityInput.unit=days input.ValidityInput.label=Certificate Validity (days) input.ValidityInput.description=Enter the number of days the certificate should be valid (1-1095) # Policy section policy.classes=ValidityPolicy,... policy.ValidityPolicy.classId=com.netscape.cms.profile.def.ValidityPolicy policy.ValidityPolicy.allowValidityOverride=true
Quick Troubleshooting
If the input field doesn’t appear in the enrollment UI:
- Double-check that
ValidityInputis included in theinput.classeslist (for cfg files) or properly nested in the<input>section (for XML). - Restart the Dogtag CA service after making changes (e.g.,
systemctl restart pki-tomcatd@yourInstance.service). - Verify that the enrollee has permissions to modify the validity period (check the profile’s ACL settings if needed).
内容的提问来源于stack exchange,提问作者Chris

