Mappers
Chapter
15
Publishing
645
Table 15-10
LdapDNCompsMap Configuration Parameters
Parameter
Description
baseDN
Specifies the DN to start searching for an entry in the publishing
directory. If you leave the
dnComps
field blank, the server uses the
base DN value to start its search in the directory.
dnComps
Specifies where in the publishing directory the Certificate
Manager should start searching for an LDAP entry that matches
the CA’s or the end entity’s information.
The server uses the
dnComps
values to form an LDAP entry to
begin a subtree search. The server gathers values for these
attributes from the certificate subject name and uses the values to
form an LDAP DN, which then determines where in the LDAP
directory the server starts its search. For example, if you set
dnComps
to use the
O
and
C
attributes of the DN, the server starts
the search from the
O=
<
org
>,
C=
<
country
> entry in the
directory, where <
org
> and <
country
> are replaced with values
from the DN in the certificate.
If you leave the
dnComps
field empty, the server checks the
baseDN
field and searches the directory tree specified by that DN
for entries matching the filter specified by
filterComps
parameter values.
Permissible values: Valid DN components or attributes separated
by commas.
filterComps
Specifies components the Certificate Manager should use to filter
entries from the search result. The server uses the
filterComps
values to form an LDAP search filter for the subtree. The server
constructs the filter by gathering values for these attributes from
the certificate subject name; it uses the filter to search for and
match entries in the LDAP directory.
If the server finds one or more entries in the LDAP directory that
match the information gathered from the certificate, the search is
successful and the server optionally performs a verification. For
example, if
filterComps
is set to use the email and user ID
attributes (
filterComps=e
,
uid
), the server searches the
directory for an entry whose values for email and user ID match
the information gathered from the certificate.
Permissible values: Valid directory attributes (in the certificate
DN) separated by commas. The attribute names for the filters need
to be attribute names from the certificate, not from ones in the
LDAP directory. For example, most certificates have an
E
attribute
for the user’s email address; LDAP calls that attribute
.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...