Publishing Cross-Pair Certificates
357
•
Authentication.
The way the Certificate Manager authenticates to the Directory Server. The
choices are
Basic authentication
and
SSL client authentication
.
If the Directory Server is configured for basic authentication or for SSL communication without
client authentication, select
Basic authentication
and specify values for the Directory
manager DN and password.
If the Directory Server is configured for SSL communication with client authentication, select
SSL client authentication
and the
Use SSL communication
option, and identify the
certificate that the Certificate Manager must use for SSL client authentication to the directory.
The server attempts to connect to the Directory Server. If the information is incorrect, the server
displays an error message.
15.7. Publishing Cross-Pair Certificates
The cross-pair certificates can be published as a
crossCertificatePair
entry to an LDAP
directory or to a file; this is enabled by default. If this has been disabled, it can be reenabled through
the Certificate Manager Console by doing the following:
1. Open the CA Console
pkiconsole https://server.example.com:9443/ca
2. In the
Configuration
tab, select the
Certificate Manager
link in the left pane, then the
Publishing
link.
3. Click the
Rules
link under
Publishing
. This opens the
Rules Management
pane on the right.
4. If the rule exists and has been disabled, select the
enable
checkbox. If the rule has been deleted,
then click
Add
and create a new rule.
a. Select
xcerts
from the
type
drop-down menu.
b. Make sure the
enable
checkbox is selected.
c. Select
LdapCaCertMap
from the
mapper
drop-down menu.
d. Select
LdapCrossCertPairPublisher
from the
publisher
drop-down menu.
The mapper and publisher specified in the publishing rule are both listed under
Mapper
and
Publisher
under the
Publishing
link in the left navigation window of the CA Console. The mapper,
LdapCaCertMap
, by default designates that the
crossCertificatePair
be stored to the
LdapCaSimpleMap
LDAP entry. The publisher,
LDAPCrossPairPublisher
, by default sets the
attribute to store the cross-pair certificate in the CA entry to
crossCertificatePair;binary
.
15.8. Testing Publishing to Files
To verify that the Certificate Manager is publishing certificates and CRLs correctly to file, do the
following:
1. Open the CA's end-entities page, and request a certificate.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...