Chapter 9. Authentication for Enrolling Certificates
242
It is also possible for a router to submit a certificate request directly to the CA. In that case, the CA
uses the
flatFileAuth
authentication module to process a text file which contains the router's
authentication credentials.
9.2.4.1. Configuring the flatFileAuth Module
Flat file authentication is already configured for SCEP enrollments, but the location of the flat file and
its authentication parameters can be edited.
1. Open the CA Console.
pkiconsole https://server.example.com:9445/ca
2. In the
Configuration
tab, select
Authentication
in the navigation tree.
3. Select the
flatFileAuth
authentication module.
4. Click
Edit/View
.
5. To change the file location and name, reset the
fileName
field.
To change the authentication name parameter, reset the
keyAttributes
value to another
value submitted in the SCEP enrollment form, like CN. It is also possible to use multiple name
parameters by separating them by commas, like
UID,CN
. To change the password parameter
name, reset the
authAttributes
field.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...