Chapter 15. Publishing
346
Publisher
Description
LdapDeltaCrlPublisher
Used to publish Delta CRLs to the LDAP
directory.
LdapUserCertPublisher
Used to publish all types of end-entity certificates
to the LDAP directory.
LdapCrossCertPairPublisher
Used to publish cross-signed certificates to the
LDAP directory.
Table 15.1. LDAP Publishers
The publishers are enabled and configured using the X.500 standard attributes for storing certificates
and CRLs. The preconfigured publishers do not need modified.
15.4. Configuring Mappers
Mappers are only used with LDAP publishing. Mappers define a relationship between a certificate's
subject name and the DN of the directory entry to which the certificate is published. The Certificate
Manager needs to derive the DN of the entry from the certificate or the certificate request so it can
determine which entry to use. The mapper defines the relationship between the DN for the user entry
and the subject name of the certificate or other input information. This relationship can derive the exact
DN of the entry or set a search for the directory to find the DN of the entry.
During installation, the Certificate Manager automatically creates a set of mappers defining the most
common relationships. The default mappers are listed in
Table 15.2, “Default Mappers”
.
Mapper
Description
LdapUserCertMap
Locates the correct attribute of user entries in the
directory in order to publish user certificates.
LdapCrlMap
Locates the correct attribute of the CA's entry in
the directory in order to publish the CRL.
LdapCaCertMap
Locates the correct attribute of the CA's entry
in the directory in order to publish the CA
certificate.
Table 15.2. Default Mappers
To use the default mappers, configure each of the macros by specifying the DN pattern and whether to
create the CA entry in the directory.
To use other mappers, create and configure an instance of the mapper. For more information see
Section 15.13.2, “Mapper Plug-in Modules ”
.
Modify a mapper by doing the following:
1. Log into the Certificate Manager Console.
pkiconsole https://server.example.com:9443/ca
2. In the
Configuration
tab, select
Certificate Manager
from the navigation tree on the left. Select
Publishing
, and then
Mappers
.
The
Mappers Management
tab, which lists configured mappers, opens on the right.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...