Chapter 2. Making Rules for Issuing Certificates
48
2.3. Configuring Custom Enrollment Profiles to Use with an
RA
The profiles used to submit certificate requests through the RA are created and configured in the
CA, as described in
Section 2.2, “Setting up Certificate Profiles”
. However, the way to process those
requests and the specific profiles to use for the requests (both for existing and custom profiles) must
be configured in the RA by calling on the RA's
request queue plug-ins
.
2.3.1. Default RA Profiles
There are already four types of certificates that are processed in the RA: SCEP (router), server, user,
and RA agent.
Profile ID
Profile Name
Description
caDualRAuserCert
RA Agent-Authenticated User
Certificate Enrollment
Enrolls user certificates with RA
agent authentication.
caRAagentCert
RA Agent-Authenticated Agent
User Certificate Enrollment
Enrolls RA agent user
certificates with RA agent
authentication.
caRACert
Manual Registration Manager
Signing Certificate Enrollment
Enrolls Registration Manager
certificates.
caRARouterCert
RA Agent-Authenticated Router
Certificate Enrollment
Enrolls router certificates after
agent approval (as opposed to
automatic enrollment).
caRAserverCert
RA Agent-Authenticated Server
Certificate Enrollment
Enrolls server certificates with
RA agent authentication.
caRouterCert
One Time Pin Router Certificate
Enrollment
Enrolls router certificates
using an automatically-
generated, one-time PIN that
the router can use to retrieve its
certificate.
Table 2.3. Profiles for the RA
2.3.2. Creating RA Enrollment Forms
Each certificate type configured for the RA has a subdirectory in
/var/lib/pki-ra/docroot/ee/
which contains index files and enrollment and processing forms. Each rendered page has two files, a
.cgi
script file and
.vm
HTML template file.
It is easiest to simply copy the docroot directory for one of the existing profiles and adapt it to the new
profile.
To configure new enrollment forms for the RA:
1. Open the end-entities docroot directory.
cd /var/lib/pki-ra/docroot/ee/
2. Copy an existing directory to make a new profile directory. For example:
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...