Enrollment Overview
384
Netscape Certificate Management System Administrator’s Guide • February 2003
•
Agent-approved enrollment is the method in which end-entity enrollment
requests are sent to an agent for approval. The agent approves the certificate
request.
•
Automatic enrollment is the method in which end-entity enrollment requests
are authenticated using a plug-in for that type of authentication, and then the
certificate request is processed; an agent is not involved in the enrollment
process.
•
Agent initiated enrollment is the method in which end-entities enroll in person
with the agent filling in information and authenticating the user. This method
is only available in the Registration Manager subsystem.
•
CMC Enrollment where a third party application can create a request that is
signed by an agent and then automatically processed.
A Certificate Manager is initially configured for agent-approved enrollment and
for
CMCAuth
; a Registration Manager is initially configured for agent-approved
enrollment,
CMCAuth
, and for in person enrollment.
You can set up automated enrollment by enabling and configuring an instance of
one of the authentication plug-in modules. You can also create plug-ins for
automatic enrollment using other forms of authentication, such as a secure ID card
or a relational database using the CMS SDK.
You configure authentication in the subsystem that actually processes end-entity
requests. If you have set up a Registration Manager to process requests, you
configure authentication in that Registration Manager. The Registration Manager
does all of the authentication processing. The Registration Manager then sends a
signed request to the Certificate Manager via a trusted connection. The Certificate
Manager simply processes the request, it does not authenticate the user, or check
that the user was authenticated.
You can configure more than one authentication method in a single instance of a
subsystem. The HTML registration pages contain hidden values specifying the
method used. If you were to set up multiple methods, you would create separate
end-entity registration pages, each specifying a different method. If you use the
certificate profile feature, the end-entity enrollment pages are dynamically
generated for each certificate profile you configure and enable. The authentication
method associated with this certificate profile is specified in the dynamically
generated enrollment page.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...