Profile ID
Profile Name
Description
ment
ing smart card-based enrollments initi-
ated through the TPS server for sign-
ing certificates.
Table 2.1. List of Certificate Profiles
3.1. Example Profile
An example
caUserCert
profile, as shipped with the server, is described here. A profile usually contains inputs, policy
sets, and outputs. The default
caUserCert
certificate profile contains the following:
•
Profile description.
This profile is for issuing user, or client, certificates.
•
Profile inputs.
•
Key generation. This sets that the key pair generation during the request submission is CRMF-based and 1024-bit.
This is a read-only field.
•
Subject name. The subject name input is used when distinguished name (DN) parameters need to be collected from
the user; the user DN can be used to create the subject name in the certificate. This input uses the following form
fields:
•
UID. The user ID of the user in the LDAP directory.
•
Email. The email address of the user.
•
Common name. The name of the user.
•
Organizational unit. The organizational unit to which the user belongs.
•
Organization. The organization name.
•
Country. The country where the user is located.
•
Requester. This input uses the following form fields:
•
Requester name. The name of the certificate requester.
•
Requester email. The email address of the certificate requester.
•
Requester phone. The phone number of the certificate requester.
•
Profile policy sets.
The different policy sets that are set by default on
caUserCert
are listed in Table 2.2, “caUserCert - Profile Policy
Sets”.
Profile Policy Set
Defaults
Constraints
set1 - SubjectName
No defaults
Subject name should match the
regular expression of the form
uid=.*
.
set2 - Validity
range = 180 days
The range is less than 365 days.
The
notbefore
and
notafter
date checks are turned off.
set3 - Key
No defaults
keytype = RSA
3.1. Example Profile
14
Chapter 2. CA: Working with Certificate
Summary of Contents for CERTIFICATE SYSTEM 7.2 - AGENT GUIDE
Page 1: ...Red Hat Certificate System Agent Guide 7 2 ...
Page 3: ......