Configuring the Certificate Manager
Chapter
3
Certificate Manager
119
The agent-approved enrollment and CMC enroll methods are enabled and
configured when you install the Certificate Manager. In order to enable and
configure one of the automated enrollment methods, you need to enable and
configure that authentication instance. You can also provide certificate based
authentication for either agent-approved or automated enrollments. For detailed
information on setting up authentication, see Chapter 9, “Authentication.”
Agent-Approved Enrollment
The Certificate Manager is enabled by default for agent-approved enrollment. The
agent-approved enrollment forms are used to enroll end entities that require
manual approval and whose requests have been sent to the agent services interface
for processing. Agent-approved certificate profile enrollments are also sent to the
agent services interface for processing.
Automated Enrollment
You set up enrollment by configuring instances of the authentication plug-ins. The
plug-ins allow you to set up the kind of authentication you will use for
authentication. All of the authentication plug-ins also enable an automated
enrollment when they are enabled. You can enable one of the authentication
plug-ins, and configure it to be able to authenticate.
Once you have set up an authentication instance, end entities use a form associated
with this method when enrolling. You must provide the necessary fields to collect
the information required for the method of authentication in the form, otherwise
you can customize the form as you like. If you are using the certificate profile
feature, the forms are dynamically generated using the inputs you specify for a
certificate profile.
The authentication methods that you can configure are:
•
Directory Based Enrollment.
End-entities are authenticated against an LDAP
directory using their user ID or DN and password. See “Setting Up Directory
Based Enrollment,” on page 389.
•
NIS Based Enrollment.
End-entities are authenticated against an NIS server.
See “Setting Up NIS Based Enrollment,” on page 391.
•
Pin Based Enrollment.
End-entities are authenticated against and LDAP
directory using their user ID, password and a pin given to them. See “Setting
Up Pin Based Enrollment,” on page 395.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...