Automated Enrollment
400
Netscape Certificate Management System Administrator’s Guide • February 2003
ldap.basedn.
Specifies the base DN for searching the authentication
directory—the server uses the value of the
uid
field from the HTTP input
(what a user enters in the enrollment from) and the base DN to construct an
LDAP search filter.
ldap.minConns.
Specifies the minimum number of connections permitted to
the authentication directory.Permissible values:
1
to
3
.
ldap.maxConns.
Specifies the maximum number of connections permitted to
the authentication directory.Permissible values:
3
to
10
.
7.
Click OK. The authentication instance is now set up and enabled.
Setting Up Portal Enrollment
Portal enrollment enables you to issue certificates and create directory entries for
users who do not yet have an entry in your directory. Portal enrollment involves
registering users by adding them to your directory while simultaneously issuing
them a certificate. When a user requests a certificate, the information they provide
is used to add the user to the directory, if an entry does not presently exist for that
user, and to issue the user a certificate. Portal enrollment is useful when you have a
portal and want to register users and have them later authenticate using a
certificate. Since you register anyone who comes to the site, this method does not
provide any authentication of users when you enroll them, unless they already
have entries in the LDAP directory. It provides authentication, in the form of their
LDAP entries and certificates when they log into the site proving only that they are
registered users.
The
PortalEnroll
module does the following:
•
Performs dual operations, registration and authentication, eliminating the
need for users to use separate forms to register for an online service and to
request a certificate; the module enables deployment of certificates along with
registration in an LDAP-compliant directory.
•
Verifies the uniqueness of the new user’s chosen user name against an
LDAP-compliant user directory and uses the user name as the only
authentication token required to obtain a certificate.
•
Uses the information from the enrollment form to create new user entries and
update directory entry attributes for unique user names.
•
Leverages an existing LDAP-compliant user directory, typically used for
storing user information.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...