Chapter 16. Authentication for Enrolling Certificates
384
f.
Click
OK
.
4. Customize the enrollment forms by configuring the inputs in the certificate profiles. Include the
information that will be needed by the plug-in to authenticate the user. If the default inputs do not
contain all of the information that needs to be collected, submit a request created with a third-party
tool.
16.4. Setting up CMC Enrollment
CMC enrollment sets up an enrollment client, signs the certificate request with an agent certificate,
and then sends the signed request to the Certificate Manager. When this method is set up, the
Certificate Manager automatically issues certificates when a valid request signed with the agent
certificate is received.
The CMCAuth authentication plug-in also activates CMC revocation. CMC revocation sets up a
revocation client, signs the request with the agent certificate, and then sends the signed request to
the Certificate Manager. When this method is set up, the Certificate Manager automatically revokes
certificates when a valid request signed with the agent certificate is received.
To set up CMC enrollment:
1. Set up the certificate profile to use to enroll users by setting policies for specific certificates in the
certificate profile. See
Chapter 13, Certificate Profiles
for information about profile policies.
2. If necessary, set up the CMCAuth authentication plug-in. An instance of this plug-in module is
created and enabled by default. It has no configuration parameters. When the instance is enabled,
CMC enrollment and CMC revocation are both enabled for the server.
a. Open the CA Console.
pkiconsole https://server.example.com:9443/ca
b. In the
Configuration
tab, select
Authentication
in the navigation tree.
The right pane shows the
Authentication Instance
tab listing currently configured
authentication instances.
c. Click
Add
.
The
Select Authentication Plug-in Implementation
window appears.
d. Select the CMCAuth plug-in module.
e. In the
Authentication Instance ID
field, type a unique name for this instance that will identify
it if the default name is not to be used.
There are no configuration options for this plug-in; it simply enables this functionality.
f.
Click
OK
. The authentication instance is now set up and enabled.
3. Use the
CMCEnroll
utility to sign certificate requests with the agent certificate.
This utility has the following syntax:
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...