data:image/s3,"s3://crabby-images/66506/665060714e4a6becf42b0b8f93c01a0c7c7425f9" alt="Netscape NETSCAPE CONSOLE 6.0 - MANAGING SERVERS Manual Download Page 203"
Using Client Authentication
Chapter
10
Using SSL and TLS with Netscape Servers
203
Example certmap.conf Mappings
The following examples illustrate three different ways you can use the
certmap.conf
file.
Example of a Default Mapping
Here are the contents of a simple
certmap.conf
file that contains only the default
mapping:
certmap default
default
default:DNComps
ou, o, c
default:FilterComps e, uid
default:verifycert
on
Using this example, the server starts its search at the directory branch point
containing the entry
ou=organizationalUnit, o=organization, c=country
,
where the italics represent values from the subject’s DN in the client certificate.
The server then uses the values for
e
(email address) and
uid
(user ID) from the
certificate to search for a match in the directory before authenticating the user.
When it finds a matching entry, the server verifies the certificate by comparing the
certificate the client sent to the certificate stored in the directory.
Example of an Additional Mapping
Here are the contents of a sample
certmap.conf
file that defines a default mapping
as well as a mapping for MyCA:
certmap default
default
default:DNComps
default:FilterComps e, uid
certmap MyCA
ou=MySpecialTrust,o=MyOrg,c=US
MyCA:DNComps
ou,o,c
MyCA:FilterComps
e
MyCA:verifycert
on
When the server gets a certificate from a CA other than MyCA, the server uses the
default mapping, which starts at the top of the directory tree and searches for an
entry matching the client’s email address (
e
) and user ID (
uid
). If the certificate is
from MyCA, the server starts its search at the directory branch containing the
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...