Configuring Authentication for End-User Enrollment
522
Netscape Certificate Management System Installation and Setup Guide • October 2001
Step 1. Before You Begin
Before setting up a Certificate Manager or Registration Manager to use a specific
authentication method:
•
Determine the authentication module you want to use. To find out about the
modules that are installed with the server, see Chapter 1, “Authentication
Plug-in Modules” of CMS Plug-ins Guide. If you want to develop and use a
custom plug-in module, be sure to check the tutorials provided in this
directory:
<server_root>/cms_sdk/cms_jdk/samples/authentication
❍
If you decided to use the directory-based authentication module, note the
authentication directory credentials, such as the host name, port number,
base DN, the user entry to bind as and the corresponding password, the
DN pattern to retrieve from the directory to construct certificate subject
names, LDAP version number, and minimum and maximum number of
connections permitted.
❍
If you decided to use the directory- and PIN-based authentication module,
note the authentication directory credentials, such as the host name, port
number, based DN, the user entry to bind as and the corresponding
password, LDAP version number, and minimum and maximum number
of connections permitted.
Next, read Chapter 4 , “PIN Generator Tool” of CMS Command-Line Tools
Guide. Determine the options you want to use to generate PINs and
construct the command for generating the PINs. Note that the
optfile
option enables you to put all the arguments in a file (instead of typing the
arguments at the command prompt) and then point the tool to read
arguments from the file.
❍
If you decided to use the NIS server-based authentication module, note the
NIS server host name and domain name. If you have an LDAP directory
deployed and want to use that for formulating the certificate subject
names, note the directory-specific information.
NOTE
If you do not configure a Certificate Manager or Registration
Manager to use any of the registered authentication plug-in
modules, the server uses manual authentication for end-user
enrollment. This means that all end-user enrollment requests are
queued for agent approval. For more information, see section
“Manual Authentication” in Chapter 1, “Authentication Plug-in
Modules” of CMS Plug-ins Guide.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...