Bind DN
361
15.10.3. Bind DN
The Certificate Manager accesses the Directory Server using a DN that has read-write permissions to
the directory. To publish certificates and CRLs to the directory, the Certificate Manager needs to use
a directory user entry that has write access to the directory. This enables the Certificate Manager to
modify the user entries with certificate-related information and the CA entry with CA's certificate and
CRL related information.
This entry can be either of the following:
• An existing DN that has write access, such as the Directory Manager.
• A new user which is granted write access. The entry can be identified by the Certificate
Manager's DN, such as
cn=testCA, ou=Research Dept, o=Example Corporation,
st=California, c=US
.
NOTE
Carefully consider what privileges are given to this user. This user can be restricted
in what it can write to the directory by creating ACLs for the account. For instructions
on giving write access to the Certificate Manager's entry, see the Directory Server
documentation.
15.10.4. Directory Authentication Method
Depending on how the Certificate Manager should authenticate to the directory, set up Directory
Server for one of the following methods of communication:
• Publishing with basic authentication
• Publishing over SSL without client authentication
• Publishing over SSL with client authentication
See the Red Hat Directory Server documentation for instructions on setting up these methods of
communication with the server.
15.11. Updating Certificates and CRLs in a Directory
The Certificate Manager and the publishing directory can become out of sync if certificates are issued
or revoked while the Directory Server is down. Certificates that were issued or revoked need to be
published or unpublished manually when the Directory Server comes back up.
To find certificates that are out of sync with the directory � valid certificates that are not in the directory
and revoked or expired certificates that are still in the directory � the Certificate Manager keeps
a record of whether a certificate in its internal database has been published to the directory. If the
Certificate Manager and the publishing directory become out of sync, use the
Update Directory
option
in the Certificate Manager agent services page to synchronize the publishing directory with the internal
database.
The following choices are available for synchronizing the directory with the internal database:
• Search the internal database for certificates that are out of sync and publish or unpublish.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...