Setting Up Publishing
624
Netscape Certificate Management System Administrator’s Guide • February 2003
4.
For LDAP publishing, you need to set up Mappers to enable an entries’ DN to
be derived from the certificate’s subject name. Generally, you will need to set
one up for the CA certificate, CRLs and for user certificates. You can also set
more than one up for a particular type. You might do this, for example, if you
have two sets of users from different divisions of your company who are
located in different parts of the directory tree. You might create one Mapper for
each of the groups that specifies a different branch of the tree.
For complete details about setting up Mappers, see “Configuring Mappers,” on
page 634.
5.
You set up Rules to determine what exactly gets published where. Rules work
independently, not in tandem. A certificate or CRL that is being published is
matched against every rule. Any rule to which it matches is activated. In this
way, the same certificate can be published to a file and to an LDAP directory
by matching a file-based rule and matching a directory-based rule.
You can set up rules for each object type: CA certificate, CRL, user certificate,
and cross-pair certificate, or you can even further divide the rules so that you
have different rules for different kinds of certificates, or different kinds of
CRLs.
The rule first determines if the object meets the rule, and then where it is to be
published. Determining if the object meets the rule is done by matching the
type and predicate set up in the rule with the object itself. Determining where
matching objects are published is determined by the Publisher and Mapper
that is associated with this rule.
For complete details about setting up Rules, see “Modifying Publishing Rules
for Certificates and CRLs,” on page 646.
6.
If you are publishing CRLs, you must set up CRLs before you can publish
them. See Chapter 14, “Revocation and CRLs” for complete details.
7.
For LDAP publishing, you need to configure the Directory Server you will be
publishing to. See “Configuring the Directory for LDAP Publishing,” on page
657 for details.
8.
Enable Publishing. You should enable publishing after setting up Publishers,
Mappers and Rules. Once it is enabled, the server will start publishing. If you
have not finished setting up, publishing may not work correctly, or at all.
For complete details, see “Enabling Publishing,” on page 653.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...