Setting up CEP Enrollment Manually
Chapter
25
Setting Up CEP Enrollment
813
•
The Directory Server port—note the port number assigned to the configuration
directory; it must be 389. If you installed Certificate Management System with
the default choices, you may skip this step; the default port assigned to the
configuration directory is 389. To find out the port number assigned to
Directory Server, check it’s configuration file (which is at
<server_root>/slapd-*/slapd.oc.conf
). Alternatively, you can also find
and change the port number from Netscape Console.
Step 2. Configure the Certificate Manager for
Publishing Certificates and CRLs
In this step, you configure the Certificate Manager to issue router and VPN-client
certificates with CRL Distribution Point Extension and to publish the certificates to a
directory.
•
Create an instance of the mapper plug-in named
LdapExactMapper
and of the
publisher plug-in named
LdapUserCertPublisher
. Once you create these
instances, you should create a publishing rule for publishing router certificates.
For instructions, see “Step B. Add Mappers, Publishers, and Publishing Rules”
on page 642.
Note that the publishing rule must be configured to use the mapper and
publisher you create for router certificates. In addition, the predicate
expression must be set to
HTTP_PARAMS.certType==CEP-Request
.
•
Configure CRL publishing details; for instructions, see “Step 4. Configure the
Certificate Manager to Publish CRLs” on page 648.
•
Identify the directory for publishing. For instructions, see “Step 5. Identify the
Publishing Directory” on page 656.
•
Create an instance of the policy plug-in named
CRLDistributionPointsExt
(following the instructions in “Step 4. Add New Policy Rules” on page 594) for
router certificates. This extension, if present in a certificate, enables the user of
the certificate to find revocation information pertaining to that certificate.
When you create an instance of the
CRLDistributionPointsExt
plugin, be
sure to leave the
issuerName
and
issuerType
fields blank and to enter
HTTP_PARAMS.certType==CEP-Request
in the
predicate
field.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...