
Automated Enrollment
404
Netscape Certificate Management System Administrator’s Guide • February 2003
Setting Up CMC Enrollment
CMC enroll allows you to set up your own enrollment client, sign the certificate
request with your agent certificate, and then send the signed request to the
Certificate Manager. When this method is setup, the Certificate Manager will
automatically issue certificates when a valid request signed with the agent
certificate is received.
The CMCAuth authentication plug-in also activates CMC Revoke. CMC Revoke
allows you to set up your own revocation client, sign the certificate request with
your agent certificate, and then send the signed request to the Certificate Manager.
When this method is setup, Certificate Manager will automatically revoke
certificates when a valid request signed with the agent certificate is received.
To set up CMC enroll you do the following:
•
Set any policies for certificate extensions, or for constraints on certificates, see
Chapter 11, “Policies” for information about policies. Alternatively, you can
enroll users through the certificate profile functionality setting policies for
specific certificates in the certificate profile, see Chapter 10, “Certificate
Profiles” for information about policies.
•
Set up the
CMCAuth
Authentication plug-in. (An instance of this plug-in
module is created and enabled by default. It has no configuration parameters.
When the instance is enabled, CMC enrollment and CMC revocation are both
enabled for the server.) See “Setting Up the PortalEnroll Authentication,” on
page 401 for details.
•
Use your agent certificate to sign certificate requests using the
CMCEnroll
utility. See “CMC Enroll Utility,” on page 405 for information on signing
requests.
Setting Up the CMCAuth Authentication Plug-in
Note: This method of authentication is setup by default. You only need to perform
the following procedure if you deleted the instance that was set up by default.
To setup this form of authentication:
1.
In the CMS window for the Certificate Manager issuing the certificates, select
the Configuration tab.
2.
Select Authentication in the navigation tree.
The right pane shows the Authentication Instance tab listing currently
configured authentication instances.
3.
Click Add.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...