Chapter 5, Working with Server Security
141
Changing the Trust Database/Key Pair File Password
Example #3
The following example uses the
CmapLdapAttr
property to search the LDAP
database for an attribute called
certSubjectDN
whose value exactly matches
the entire subject DN taken from the client certificate.
certmap myco ou=My Company Inc, o=myco, c=US
myco:CmapLdapAttr certSubjectDN
myco:DNComps o, c
myco:FilterComps mail, uid
myco:verifycert on
If the client certificate subject is:
uid=Henry Jones Junior, o=Ark Inc, c=US
the server first searches for entries that contain the following information:
certSubjectDN=uid=Henry Jones Junior, o=Ark Inc, c=US
If one or more matching entries are found, the server proceeds to verify the
entries. If no matching entries are found, the server will use
DNComps
and
FilterComps
to search for matching entries. In this example, the server
would search for
uid=Henry Jones Junior
in all entries under
o=Ark Inc, c=US
.
Note
This example assumes the LDAP directory contains entries with the attribute
certSubjectDN
.
Changing the Trust Database/Key Pair File
Password
It’s a good practice to change your trust database/key pair file password
periodically. If your Enterprise Administration Server is SSL enabled, this
password is required when starting the server. Changing your password
periodically adds an extra level of server protection.
For a list of guidelines to consider when changing a password, see “Guidelines
for Creating Hard-to-Crack Passwords,” on page 144
Summary of Contents for Netscape Enterprise Server
Page 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Page 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Page 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Page 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Page 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Page 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Page 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Page 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Page 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Page 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Page 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Page 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Page 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Page 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Page 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Page 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Page 504: ...504 Netscape Enterprise Server Administrator s Guide ...