Configuring Publishing to an LDAP Directory
213
Certificate Type
Schema
Reason
object classes. The Certificate Manager does
not automatically add this object class to the
schema table of the corresponding Directory
Server.
If the directory object that it finds does not
allow the
userCertificate;binary
attribute, adding or removing the certificate
fails.
CA
caCertificate;binary (attribute)
This is the attribute to which the Certificate
Manager publishes the certificate.
The Certificate Manager publishes its own
CA certificate to its own LDAP directory entry
when the server starts. The entry corresponds
to the Certificate Manager's issuer name.
This is a required attribute of the
certificationAuthority
object class.
The Certificate Manager adds this object class
to the directory entry for the CA if it can find
the CA's directory entry.
CRL
certificateRevocationList;binary
(attribute)
This is the attribute to which the Certificate
Manager publishes the CRL.
The Certificate Manager publishes the CRL
to its own LDAP directory entry. The entry
corresponds to the Certificate Manager's
issuer name.
This is an attribute of the
certificationAuthority
object
class. The value of the attribute is the
DER-encoded binary X.509 CRL. The
CA's entry must already contain the
certificationAuthority
object class for
the CRL to be published to the entry.
3. Set up a bind DN for the Certificate Manager to use to access the Directory Server.
The Certificate Manager user must have read-write permissions to the directory to publish
certificates and CRLs to the directory so that the Certificate Manager can modify the user
entries with certificate-related information and the CA entry with CA's certificate and CRL related
information.
The bind DN entry can be either of the following:
• An existing DN that has write access, such as the Directory Manager.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...