![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 127](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697127.webp)
How The Certificate Manager Works
Chapter
3
Certificate Manager
127
The Certificate Enrollment Process
When an end-entity enrolls in your PKI requesting a certificate, a number of things
can happen depending on your configuration and the subsystems you have
installed. The following lists those events in the approximate order they occur:
•
The end entity provides the information in one of the enrollment forms and
submits a request. The information gathered from the end entity is
customizable in the form depending on the information you want to collect, or
you need to collect to store in the certificate that is issued or to authenticate
against the authentication method associated with the form. The form creates a
request that is then submitted to the Certificate Manager.
•
The enrollment form can trigger the creation of the public and private keys for
this request, or for dual-key pairs.
•
The end entity may have to provide some form of authentication before
submitting the request. You can configure LDAP authentication, Pin-based
authentication, certificate-based authentication, or NIS-based authentication.
•
The request may be submitted using an agent-approved enrollment process or
an automated process.
❍
The agent-approved process, which involves no end-entity authentication,
sends the request to the request queue in the agent services interface where
an agent must processes the request. An agent can then change the status
of the request, reject the request, or approve the request. The agent can also
change some aspects of the request.
You can set up an automated notification that send an email any time a
request appears in the queue to the agent, or an automated job that sends a
list of the contents of the queue to agents on a pre configured schedule. See
Chapter 12, “Automated Notifications” and Chapter 13, “Automated
Jobs.”
❍
The automated process, which involves end-entity authentication, allows
the certificate to be processed upon successful authentication of the end
entity.
•
The form can collect information about the end entity from an LDAP directory
when the form is submitting. You can set up policies using predicates that
request this information from the LDAP directory when the user authenticates
using an LDAP user ID and password. For certificate profile based enrollment,
you set up defaults that are used to collect this information.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...