You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为Dogtag证书配置文件设置notBefore/notAfter及XML请求技术问询

Hey Chris, great question—let me break this down for you step by step since I’ve tinkered with Dogtag’s profile configuration quite a bit.

Dogtag Certificate Profile: Adding a Validity Period Input Field

1. Correct ClassID for User-Configurable Validity

If you want to let requesters specify a custom validity period during enrollment, the exact ClassID you need is com.netscape.cms.profile.def.ValidityInput.

A quick note: There’s a related class com.netscape.cms.profile.def.ValidityDefault that sets a fixed default validity with no user input, but since you asked for an input field, ValidityInput is the right pick.

Dogtag’s best built-in resources for this are:

  • Default profile files in /var/lib/pki/pki-tomcat/ca/profiles/ca (like caUserCert.cfg or caServerCert.cfg). Look for sections using validity classes to see real-world examples of how they’re configured.
  • The Dogtag source code’s profile definition classes (if you’re comfortable digging into code) to understand the inner workings of these classes.

3. XML Request Configuration

To add the validity input field to your profile, you’ll need to update two key sections of the profile XML: the input phase (to collect the user’s value) and the policy phase (to enforce that value on the certificate). Here’s a concrete example that fits most user certificate profiles:

<Profile>
  <!-- ... existing profile sections (authentication, etc.) ... -->
  <input>
    <class id="ValidityInput" name="Validity Period Input" classId="com.netscape.cms.profile.def.ValidityInput">
      <property name="defaultValidity" value="365"/> <!-- Default days if user doesn't specify -->
      <property name="minValidity" value="1"/> <!-- Minimum allowed validity in days -->
      <property name="maxValidity" value="1095"/> <!-- Maximum allowed validity (3 years) -->
      <property name="unit" value="days"/> <!-- Supported units: hours, weeks, months, years -->
      <property name="label" value="Certificate Validity (days)"/> <!-- Label shown in enrollment UI -->
      <property name="description" value="Enter the number of days the certificate should be valid (1-1095)"/>
    </class>
    <!-- ... other input classes (e.g., SubjectNameInput) ... -->
  </input>

  <policy>
    <class id="ValidityPolicy" name="Validity Policy" classId="com.netscape.cms.profile.def.ValidityPolicy">
      <property name="allowValidityOverride" value="true"/> <!-- *Critical*: Lets user input override CA defaults -->
    </class>
    <!-- ... other policy classes ... -->
  </policy>
  <!-- ... rest of profile configuration ... -->
</Profile>

Key Configuration Notes

  • Don’t skip the ValidityPolicy in the policy section—this is what actually applies the user’s input to the certificate.
  • Ensure allowValidityOverride is set to true; without this, the CA will ignore the user’s input and use its default validity period.
  • Adjust minValidity, maxValidity, and unit to match your organization’s security requirements.

If you’re using Dogtag’s text-based .cfg profile files instead of XML, the equivalent configuration would look like this:

# Input section
input.classes=ValidityInput,...
input.ValidityInput.classId=com.netscape.cms.profile.def.ValidityInput
input.ValidityInput.defaultValidity=365
input.ValidityInput.minValidity=1
input.ValidityInput.maxValidity=1095
input.ValidityInput.unit=days
input.ValidityInput.label=Certificate Validity (days)
input.ValidityInput.description=Enter the number of days the certificate should be valid (1-1095)

# Policy section
policy.classes=ValidityPolicy,...
policy.ValidityPolicy.classId=com.netscape.cms.profile.def.ValidityPolicy
policy.ValidityPolicy.allowValidityOverride=true

Quick Troubleshooting

If the input field doesn’t appear in the enrollment UI:

  • Double-check that ValidityInput is included in the input.classes list (for cfg files) or properly nested in the <input> section (for XML).
  • Restart the Dogtag CA service after making changes (e.g., systemctl restart pki-tomcatd@yourInstance.service).
  • Verify that the enrollee has permissions to modify the validity period (check the profile’s ACL settings if needed).

内容的提问来源于stack exchange,提问作者Chris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:54:28