Configuring a Registration Manager
Chapter
4
Registration Manager
155
Setting Up Authentication
The first step in configuring enrollment is setting up authentication. You can set up
more than one type of authentication. Each type you set up must be associated with
a particular form in the interface. If you are using the certificate profile feature for
enrollments, the forms are dynamically generated with the content being
determined by the inputs you set for a particular certificate profile. You can even
set up the same method of authentication and associated more than one form with
it. You might do this if you wanted to change other aspects of the enrollment.
For example, you might want to create an automated authentication that requires
LDAP authentication. You have two classes of employees, permanent and
temporary. You want to issue both classes of employees certificates using LDAP
authentication, but you want to issue each of these classes certificates with different
validity periods and different extensions. You can create two different forms, both
using LDAP authentication, but each having different policies associated with the
form.
You can configure the authentication method to be agent-approved or automated.
The agent-approved enrollment, in-person agent initiated enrollment, and CMC
enroll methods are enabled and configured when you install the Registration
Manager. In order to enable and configure one of the automated enrollment
authentication methods, you need to enable and configure that authentication
instance. You can also provide certificate based authentication for either
agent-approved or automated enrollments. For detailed information on setting up
authentication, see Chapter 9, “Authentication.”
The authentication you set up in the Registration Manager has no bearing on the
Certificate Manager. Requests received by the Certificate Manager from the
Registration Manager will be considered to have been authenticated correctly by
the Registration Manager; the Certificate Manager will do no authentication
checking.
Agent-Approved Enrollment
The Registration Manager is enabled by default for agent-approved enrollment.
The agent-approved enrollment form is used to enroll end entities whose request is
sent to the agent services interface for processing. If you are using the certificate
profile feature, an agent-approved enrollment is associated with any certificate
profile that does not declare an authentication method. Agent-approved certificate
profile enrollments are also sent to the agent services interface for processing.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...