Chapter 1. Agent Services
6
The Certificate System can be configured to publish certificates and CRLs to an LDAP directory.
This information is usually published automatically, but the Certificate Manager agent services page
can be used to update the directory manually. See
Section 5.2, “Manually Updating the Directory”
.
• Manages certificate profiles.
The agent can enable and disable certificate profiles. A profile must be temporarily disabled before
an administrator can make changes to the profile itself using the administrative interface. After the
changes have been made, the agent can re-enable the profile for regular use. See
Chapter 2, CA:
Working with Certificate Profiles
.
1.2.2. Registration Manager Agent Services
There are two user types who can access the RA services pages: agents and administrators. Each
user requires a certificate to authenticate to the appropriate services page.
Figure 1.3. Registration Manager Agent Services Page
RA agents can perform four tasks:
• Approve and reject certificate requests.
• List, view, and add notes to certificate requests.
• List and view issued certificates.
• Revoke issued certificates.
RA agents cannot
initiate
tasks, in a sense. Their services page begins with listing requests and
certificates because the agent's job is to respond to enrollment operations initiated by users.
RA administrators can only manage users and groups for the RA subsystem.
NOTE
The RA subsystem uses its HTML-based services pages for administrative functions as
well as agent services, because it does not have a Java-based console to handle those