Creating Custom Renewal Profiles
119
4.7.1.2. Renewal Types in Certificate System
As with any certificate request, a renewal request has to be approved before the CA will issue the new
certificate. Certificate System has three renewal types, depending on the authorization method used to
verify the requester, and any of the three types can be used to renew any kind of certificate:
• Agent-based renewal, where the agent manually approves the request
• Directory-based renewal, where the requester authenticates to an LDAP directory
• Certificate-based renewal, where the certificate stored in the browser's database is used to
authenticate the requester
Authentication is covered in
Chapter 9, Authentication for Enrolling Certificates
.
TIP
Email notifications can be configured for renewal requests; this is described in
Section 10.2, “Setting up Automated Notifications for the CA”
and
Section 11.3.3,
“Configuration Parameters of certRenewalNotifier”
.
4.7.2. Creating Custom Renewal Profiles
Certificate renewal
regenerates a certificate using its original public key, certificate extensions and
constraints, and subject name. A renewed certificate is identical to the original, except that it has a
new expiration date.
When a certificate is renewed, it has to be renewed using a renewal profile that corresponds to
the initial enrollment profile. Certificate System supports renewals both for tokens and for regular
certificates, both through the RA and the CA.
The default configuration profiles cover user certificates and other types of subsystem certificates, as
well as token renewals, but it may be necessary or convenient to create a special renewal profile for a
custom enrollment form.
4.7.2.1. Default Renewal Profiles
Certificate System contains three default renewal profiles for renewing user certificates.
Renewal Profile
Type
caDirUserRenewal.cfg
Directory-based
caManualRenewal.cfg
Agent-based
caSSLClientSelfRenewal.cfg
Certificate-based
Table 4.4. Renewal Profiles
4.7.2.2. Creating an Enrollment Profile
A custom profile is configured the same as described in
Section 2.2, “Setting up Certificate Profiles”
.
There are two settings that must be present in the profile, however, to allow renewal for the certificate:
a setting on whether renewal is allowed and a setting on the time period when renewal is allowed.
The
renewal
parameter sets whether renewal is allowed. This must be
true
:
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...