
Certificate-Based Enrollment
408
Netscape Certificate Management System Administrator’s Guide • June 2003
•
Enable the appropriate enrollment option, such as directory-based enrollment
or NIS-server based enrollment. Be sure to configure the authentication
module to compose the desired DN pattern.
•
To enable you to configure CMS for certificate-based enrollment, the following
three enrollment forms are provided:
❍
CertBasedDualEnroll.htm
l—this form enables end users to request dual
certificates—one for signing another for encryption—by submitting
pre-issued certificates as authentication tokens; when a user enrolls for a
certificate, the server verifies the CA that has issued the certificate the user
uses for authentication, uses the configured directory to formulate subject
names for the new certificates, and issues the certificates.
❍
CertBasedEncryptionEnroll.html
—this form is provided as a sample. It
enables end users to request encryption certificates by submitting
pre-issued certificates as authentication tokens; when a user enrolls for a
certificate, the server verifies the CA that has issued the certificate the user
uses for authentication, uses the configured directory to formulate the
subject name for the new certificate, and issues the certificate.
❍
CertBasedSingleEnroll.html
—this form is provided as a sample. It
enables end users to request signing certificates by submitting pre-issued
certificates as authentication tokens; when a user enrolls for a certificate,
the server verifies the CA that has issued the certificate the user uses for
authentication, uses the configured directory to formulate the subject name
for the new certificate, and issues the certificate.
Enabling certificate-based enrollment creates one link, named
Certificate
,
under the list of user-enrollment links in the end-entity enrollment interface.
By default, the link points to the
CertBasedDualEnroll.html
form. If you
want to use either of the other two forms,
CertBasedEncryptionEnroll.html
or
CertBasedSingleEnroll.html
, you should associate the
Certificate
link
to the form you want to use or add more links to the
index.html
file.
Note that all three enrollment forms by default work with the directory-based
authentication module, named
UidPwdDirAuth
, explained in “Setting Up
Directory Based Enrollment” on page 387. You can use the certificate-based
enrollment forms with any of the authentication modules, for example,
directory- and PIN-based or NIS-server based authentication modules. See the
CMS Customization Guide for details.
In general, the following three hidden variables distinguish certificate-based
enrollment forms from other enrollment forms:
❍
certauthEnroll
—this variable specifies whether certificate-based
enrollment is turned
on
or
off
.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...