CEP Enrollment
Chapter
9
Authentication
419
When setting up multiple CEP services, you can use the
cepsubstore
attribute to
differentiate one CEP service from another. For example, if you’re setting up
separate CEP services for router and VPN-client certificates and want to set
different extensions in these certificates, you can make that happen with the help of
predicates.
Setting Up Publishing of CEP Certificates and
CRLs
Set up the Directory for Publishing CEP Certificates and CRLs
You need to do the following to set up the directory to publish CEP Certificates and
CRLs:
•
Set up the schema in the directory for publishing. Chapter 15, “Publishing”
contains information on setting up Netscape Directory Server for publishing
certificates and CRLs—it covers directory schema required for publishing
certificates and the attributes to which a Certificate Manager publishes
end-entity certificates and CRLs.
•
Verify that the Directory Server schema can accommodate VPN clients. You
may need to update the Directory Server’s schema. The reason for this is, if you
plan on publishing certificates from routers, they may need to be published
with the same DN as their certificate subject names. For example, if the
certificate subject name contains
UnstructuredAddress
or
UnstructuredName
components, you may need to add them to the directory schema.
unstructuredAddress, 1.2.840.113549.1.9.7, string
unstructuredName, 1.2.840.113549.1.9.8, string
Check the directory documentation for instructions on changing the schema.
•
The Directory Server port must be 389. To find out the port number assigned to
Directory Server, check it’s configuration file (which is at
<server_root>/slapd-*/slapd.oc.conf
). Alternatively, you can also find
and change the port number from Netscape Console.
•
You will need publish certificates and CRLs to the same tree in the directory;
you may customize this if you desire. We recommend that you publish to a tree
named after the
O
attribute in your CA signing certificate. Router certificates
will also need to have an
O
inserted in the subject name; this can be done
automatically.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...