Libraries
143
5.2.5. Libraries
The RA also provides the following Perl libraries to facilitate the creation of custom enrollment
workflows:
Library
Description
PKI::Base::CertStore
(
/var/lib/rhpki-ra/
lib/perl/PKI/Base/
CertStore
)
Perl interface to access the certificate store in the RA.
PKI::Base::PinStore
(
/
var/lib/rhpki-ra/lib/
perl/PKI/Base/PinStore
)
Perl interface to access the one-time PIN store.
PKI::Base::PinStore
(
/var/lib/rhpki-ra/
lib/perl/PKI/Base/
UserStore
)
Perl interface to access the user and group database.
PKI::Conn::CA
(
/var/
lib/rhpki-ra/lib/perl/
PKI/Conn/CA
)
Perl interface to access the CA for enrollment.
PKI::Request::Queue
(
/
var/lib/rhpki-ra/lib/
perl/PKI/Request/Queue
)
Perl interface to access the request queue in the RA.
Table 5.3. Perl libraries available for creating enrollment work flow
In the RA, the CGI that handles the SCEP request is running at http://example.com:12888/ee/scep/
pkiclient.cgi
Note
The RA only supports CA mode over SCEP.
5.3. Working With the Registration Authority
The following sections describe how to work with the Registration Authority, including listing, adding
and deleting users and groups, and associating users with groups. They also describe how to add new
Agents and Administrators.
Additional topics describe how to submit CSRs and to perform SCEP, Server, User, and Agent
Enrollment requests.
5.3.1. Configuring Additional RA Instances
The following sections describe how to add and configure additional RA instances to an existing
security domain.
By default, when you install an RA, it is automatically added to a default Registration Managers Group
on the CA. This means the default RA instance will have the correct identification information for
authentication and authorization.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...