DNs in Certificate Management System
Appendix
A
Distinguished Names
321
For example:
CN=Example Corporation Certificate Authority, O=Example
Corporation, C=US
Selecting DNs for Certificates
Figure A-1 illustrates the structure of distinguished names you might select for CA
certificates, server certificates, and personal certificates.
Figure A-1
Sample directory hierarchy
DN Patterns and Certificate Subject Names
You can configure Certificate Management System to issue certificates with subject
names that are formulated from the directory attributes and entry DN. The
dnpattern
configuration variable of the automated-enrollment modules, such as
UidPwdDirAuth
and
UidPwdPinDirAuth
, described in Chapter 1, “Authentication
Plug-in Modules” enable you to configure the server to issue certificates with
required subject names. Note that
dnpattern
is a string representing a subject
name pattern to formulate from the directory attributes and entry DN. If empty or
not set, Certificate Management System uses the LDAP entry DN as the certificate
subject name.
The
dnpattern
configuration variable supports escaped commas and multiple
attribute variable assertions (AVAs) in a RDN. Below is the syntax for the DN
pattern followed by examples.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...