Modifying Certificate Profiles through the Command Line
283
Parameter
Description
desc
Gives a free text description of the certificate
profile, which is shown on the end-entities
page. For example,
desc=This certificate profile
is for enrolling server certificates with agent
authentication.
enable
Sets whether the profile is enabled, and therefore
accessible through the end-entities page. For
example,
enable=true
.
auth.instance_id
Sets which authentication manager plug-in
to use to authenticate the certificate request
submitted through the profile. For automatic
enrollment, the CA issues a certificate
immediately if the authentication is successful. If
authentication fails or there is no authentication
plug-in specified, the request is queued to be
manually approved by an agent. For example,
auth.instance_id=AgentCertAuth
.
name
Gives the name of the profile. For example,
name=Agent-Authenticated Server Certificate
Enrollment
.
input.list
Lists the allowed inputs for the profile by name.
For example,
input.list=i1,i2
.
input.
input_id
.class_id
Gives the java class name for the input by input
ID (the name of the input listed in
input.list
). For
example,
input.i1.class_id=certReqInputImpl
.
output.list
Lists the possible output formats for the profile by
name. For example,
output.list=o1
.
output.
output_id
.class_id
Gives the java class name for the output
format named in
output.list
. For example,
output.o1.class_id=certOutputImpl
.
policyset.list
Lists the configured profile rules. For dual
certificates, one set of rules applies to the signing
key and the other to the encryption key. Single
certificates use only one set of profile rules. For
example,
policyset.list=serverCertSet
.
policyset.
rule_id
.list
Lists the policy sets configured for the
profile by ID number. For example,
policyset.serverCertSet.list=1,2,3,4,5,6,7,8
.
policyset.
rule_id.policy_number.
constraint.class_id
Gives the java class name of the
constraint plug-in set for the default
configured in the profile rule. For example,
policyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl
.
policyset.
rule_id.policy_number.
constraint.name
Gives the user-defined name
of the constraint. For example,
policyset.serverCertSet.1.constraint.name=Subject
Name Constraint
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...