Certificate-Based Enrollment
410
Netscape Certificate Management System Administrator’s Guide • February 2003
•
Enable the appropriate enrollment option, such as directory-based enrollment
or NIS-server based enrollment. Be sure to configure the authentication
module to compose the desired DN pattern.
•
To enable you to configure CMS for certificate-based enrollment, the following
three enrollment forms are provided:
❍
CertBasedDualEnroll.htm
l—this form enables end users to request dual
certificates—one for signing another for encryption—by submitting
pre-issued certificates as authentication tokens; when a user enrolls for a
certificate, the server verifies the CA that has issued the certificate the user
uses for authentication, uses the configured directory to formulate subject
names for the new certificates, and issues the certificates.
❍
CertBasedEncryptionEnroll.html
—this form is provided as a sample. It
enables end users to request encryption certificates by submitting
pre-issued certificates as authentication tokens; when a user enrolls for a
certificate, the server verifies the CA that has issued the certificate the user
uses for authentication, uses the configured directory to formulate the
subject name for the new certificate, and issues the certificate.
❍
CertBasedSingleEnroll.html
—this form is provided as a sample. It
enables end users to request signing certificates by submitting pre-issued
certificates as authentication tokens; when a user enrolls for a certificate,
the server verifies the CA that has issued the certificate the user uses for
authentication, uses the configured directory to formulate the subject name
for the new certificate, and issues the certificate.
Enabling certificate-based enrollment creates one link, named
Certificate
,
under the list of user-enrollment links in the end-entity enrollment interface.
By default, the link points to the
CertBasedDualEnroll.html
form. If you
want to use either of the other two forms,
CertBasedEncryptionEnroll.html
or
CertBasedSingleEnroll.html
, you should associate the
Certificate
link
to the form you want to use or add more links to the
index.html
file.
Note that all three enrollment forms by default work with the directory-based
authentication module, named
UidPwdDirAuth
, explained in “Setting Up
Directory Based Enrollment” on page 389. You can use the certificate-based
enrollment forms with any of the authentication modules, for example,
directory- and PIN-based or NIS-server based authentication modules. See the
CMS Customization Guide for details.
In general, the following three hidden variables distinguish certificate-based
enrollment forms from other enrollment forms:
❍
certauthEnroll
—this variable specifies whether certificate-based
enrollment is turned
on
or
off
.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...