Setting Up Certificate Profiles
434
Netscape Certificate Management System Administrator’s Guide • February 2003
When a certificate profile is associated with an authentication method, the request
is approved immediately and generates a certificate automatically if the user
successfully authenticates, all the information required is provided, and the
request does not violate any of the constraints set up for the certificate profile.
The issued certificate contains the content defined in the defaults for this certificate
profile, such as the extensions and validity period for the certificate, and the
content of the certificate is constrained by the constraints set up for each default.
You can set up more than one set of policies (defaults and constraints) within one
profile, distinguishing each set by using the same value in the Policy Set ID for each
set. This is particulary useful for dealing with dual keys enrollment where
encryption key and signing key are submitted into the same profile. The server
evaluates each set with each request it receives. In the case where a single
certificate is issued, one set is evaluated, any other sets are ignored. In the case
where dual-key pairs are issued, the first set is evaluated with the first certificate
request, and the second set is evaluated with the second certificate request. There is
no need for more than one set if you are issuing a single certificate, or more than
two sets if you are issuing dual-key pairs.
The request is not evaluated by the Policies set up in the Policy feature of CMS. If
the enrollment took place in a Registration Manager, both the Registration
Manager and the Certificate Manager should have the same certificate profile
implemented with the same policies. The profile in the Certificate Manager will
have the final authority.
Setting Up Certificate Profiles
You set up certificate profiles by configuring the existing certificate profiles,
deleting an existing certificate profile, or adding another certificate profile and
configuring it.
Setting up certificate profiles includes the following process:
•
Decide which certificate profiles you will need for your PKI. You will have one
certificate profile for each type of certificate you issue, and can have more than
one certificate profile for each type of certificate you issue is you want to set up
a particular type of certificate with different authentication methods, or
different defaults and constraints. Note that any certificate profile available in
the administrative interface can be approved by an agent and then used by an
end entity to enroll.
•
Delete any certificate profiles that you will not use.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...