
Mappers
Chapter 16
Publishing
617
certSubjectDN=UID=jdoe, O=Example Corporation, C=US
and then narrows down the search to an entry that has only this:
certSubjectDN=UID=jdoe, O=Example Corporation, C=US
If no matching entries are found, the server returns an error and writes it to the log.
Configuration Parameters of LdapSubjAttrMap
Table 16-9 describes these parameters.
LdapDNCompsMap
The
LdapDNCompsMap
plug-in module implements the DN components mapper. This
mapper enables you to configure a Certificate Manager to map a certificate to an LDAP
directory entry by constructing the entry’s distinguished name from components (such as
CN
,
OU
,
O
, and
C
) specified in the certificate subject name, and then using it as the search DN
to locate the entry in the directory. You can use this mapper to locate the following:
•
The CA’s entry in the directory for publishing the CA certificate and the CRL.
•
End-entity entries in the directory for publishing end-entity certificates.
In general, the mapper takes DN components to build the search DN. The mapper also takes
an optional root search DN. The server uses the DN components to form an LDAP entry to
begin a subtree search and the filter components to form a search filter for the subtree. If
none of the DN components are configured, the server uses the base DN for the subtree. If
the base DN is null and none of the DN components match, an error is returned. If none of
the DN components and filter components match, an error is returned. If the filter
components are null, a base search is performed.
Table 16-9
LdapSubjAttrMap Parameters
Parameter
Description
certSubjNameAttr
Specifies the name of the LDAP attribute that contains a certificate
subject name as its value. Must be
certSubjectName
.
searchBase
Specifies the base DN for starting the attribute search.
Permissible values: A valid DN of an LDAP entry.
Example:
O=example.com, C=US
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...