Automated Enrollment
Chapter
9
Authentication
391
Entering values for this parameter is optional.
ldap.ldapconn.host.
Specifies the fully-qualified DNS host name of the
authentication directory.
ldap.ldapconn.port.
Specifies the TCP/IP port on which the authentication
directory listens to requests from CMS.
ldap.ldapconn.secureConn.
Specifies the type—SSL or non-SSL—of the port
on which the authentication directory listens to requests from CMS. Select if
this is an SSL port, deselect if this is a non-SSL port.
ldap.ldapconn.version.
Specifies the LDAP protocol version.
2
specifies LDAP
version 2. If your authentication directory is based on Netscape Directory
Server 1.x, choose
2
.
3
specifies LDAP version 3. For Directory Server versions
3.x and later, choose
3
(default).
ldap.basedn.
Specifies the base DN for searching the authentication
directory—the server uses the value of the
uid
field from the HTTP input
(what a user enters in the enrollment from) and the base DN to construct an
LDAP search filter.
ldap.minConns.
Specifies the minimum number of connections permitted to
the authentication directory. Permissible values:
1
to
3
.
ldap.maxConns.
Specifies the maximum number of connections permitted to
the authentication directory. Permissible values:
3
to
10
.
7.
Click OK. The authentication instance is now set up and enabled.
Setting Up NIS Based Enrollment
The
NISAuth
module implements the NIS server-based authentication. You can
use the module for authenticating end users in the NIS domain during certificate
enrollment.
Optionally, you can configure the authentication module to do an LDAP
correlation—that is, use the NIS directory to authenticate users based on the user
ID and password they enter in the enrollment form, but compose certificate subject
names from an LDAP-compliant directory, such as Netscape Directory Server.
When using an LDAP directory to compose subject names, you can configure the
module to search for and retrieve specific LDAP attribute values from the
directory. The ability of the module to use an LDAP directory to form certificate
subject names is useful in cases where the NIS server only stores user IDs and
passwords and you don’t want to formulate subject names using just common
names and user IDs.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...