Automated Enrollment
390
Netscape Certificate Management System Administrator’s Guide • February 2003
1.
In the CMS window of the Certificate Manager or Registration Manager that
processes certificate requests, select the Configuration tab.
2.
Select Authentication in the navigation tree.
The right pane shows the Authentication Instance tab listing currently
configured authentication instances.
3.
Click Add.
The Select Authentication Plug-in Implementation window appears.
4.
Select
UidPwdDirAuth
for authentication based on user ID and password,
select
UdnPwdDirAuth
for authentication based on DN and password.
5.
Click Next.
The Authentication Instance Editor window appears.
6.
Fill in the following fields in the Authentication Instance Editor window:
Authentication Instance ID.
Accept the default instance name, or enter a new
name. If you choose to use a different name, be sure to edit this name in the
hidden value in the enrollment forms.
dnpattern.
Specifies a string representing a subject name pattern to formulate
from the directory attributes and entry DN. See “DNs in Certificate
Management System” on page 750.
ldapStringAttributes.
Specifies the list of LDAP string attributes that should
be considered authentic for the end entity. If specified, the values
corresponding to these attributes will be copied from the authentication
directory into the authentication token—that is, values retrieved from this
parameter can be used by policy modules to formulate subject names for
certificates or to make other policy decisions. For details, see
“SubjectAltNameExt” on page 557. Entering values for this parameter is
optional.
ldapByteAttributes.
Specifies the list of LDAP byte (binary) attributes that
should be considered authentic for the end entity. If specified, the values
corresponding to these attributes will be copied from the authentication
directory into the authentication token for use by other modules—that is,
values retrieved from this parameter can be used by policy modules to make
certain policy decisions or to add additional information to users’ certificates.
For example, assume you have defined an LDAP binary attribute for storing
users’ pictures or fingerprints in your directory. You could develop a policy
plug-in that adds users’ pictures to their certificates as extensions.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...