
Using Client Authentication
200
Managing Servers with Netscape Console • December 2001
For example, if you set
DNComps
to use the
o
and
c
RDN keywords, the server starts
the search from the
o=org, c=country
entry in the directory, where
org
and
country
are replaced with values from the DN in the certificate.
•
If there isn’t a
DNComps
entry in the mapping, the server uses either the
CmapLdapAttr
setting or the entire subject DN in the client certificate to
determine where to start searching.
•
If the
DNComps
entry is present but has no value, the server searches the entire
directory tree for entries matching the filter specified by
FilterComps
.
The following RDN keywords are supported for
DNComps: cn
,
ou
,
o
,
c
,
l
,
st
,
e
,
and
. You can list the keywords in lower case or upper case. You can use
e
or
, but not both.
FilterComps
FilterComps
is a comma-separated list of RDN keywords used to create a filter by
gathering information from the user’s DN in the client certificate. The server uses
the values for these keywords to form the search criteria for matching entries in the
LDAP directory. If the server finds one or more entries in the directory that match
the user’s information gathered from the certificate, the search is successful and the
server performs a verification (if
verifycert
is set to
on
).
For example, if
FilterComps
is set to use the
e
and
uid
attribute keywords
(
FilterComps=e,uid
), the server searches the directory for an entry whose values
for
e
and
uid
match the user’s information gathered from the client certificate.
Email addresses and user IDs are good filters because they are usually unique
entries in the directory.
The filter needs to be specific enough to match one and only one entry in the
directory. The following RDN keywords are supported for
FilterComps
:
cn
,
ou
,
o
,
c
,
l
,
st
,
e
, and
. You can list the keywords in lower case or upper case. You
can use
e
or
, but not both.
VerifyCert
VerifyCert
tells the server whether it should compare the client’s certificate with
the certificate found in the user’s directory entry. It takes one of two values:
on
or
off
. Setting the value to
on
ensures that the server will not authenticate the client
unless the certificate presented exactly matches the certificate stored in the
directory. Setting the value to
off
disables the verification process.
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...