Automated Enrollment
396
Netscape Certificate Management System Administrator’s Guide • February 2003
Creating Pins
The pin tool performs the following functions:
•
Adds the necessary schema for pins to the LDAP directory.
•
Adds a pin manger user who has read-write permissions to the pins that are set
up.
•
Sets up ACIs to allow for pin removal once the pin has been used, giving
read-write permissions for pins to the pin manager, and preventing users from
creating or changing pins.
•
Creates pins in each user entry.
The pin tool is located in the following directory:
<server_root>/bin/cert/tools
This tool comes with its own documentation in this location, and is also
documented in the CMS Command-Line Tools Guide.
To use the pin tool:
1.
Go to the following directory:
<server_root>/bin/cert/tools
2.
Open the
setpin.conf
file in a text editor.
3.
Follow the instructions outlined in the file and make the appropriate changes.
Typically, you will need to update the Directory Server’s host name, Directory
Manager’s bind password, and PIN manager’s password.
4.
Run the
setpin
command with its
optfile
option pointing to the
setpin.conf
file (
setpin optfile=setpin.conf
).
The tool modifies the schema with a new attribute (by default,
pin
) and a new
object class (by default,
pinPerson
), creates a
pinmanager
user, and sets the
ACI to allow only the
pinmanager
user to modify the
pin
attribute.
5.
If you want to generate PINs for specific user entries, or want to provide your
own PINs, you can add these pins using an input file. For information on
constructing an input file, see the PIN Generator documentation.
6.
Run the
setpin
command to create hashed pins in the directory.
You can run the tool first without the
write
option to generate a list of pins
without actually changing the directory.
For example:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...