![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 393](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697393.webp)
Automated Enrollment
Chapter
9
Authentication
393
Setting Up Pin Based Enrollment
Pin based authentication involves setting up pins for each of your users in the
LDAP directory, distributing those pins to your users, and then having the users
provide their pin along with their user ID and password when they fill out a
certificate request. Users are then authenticated both against an LDAP directory
using their user ID and password, and against the pin that is contained in their
LDAP entry. When the user successfully authenticates, their request is
automatically processed and a new certificate is issued.
CMS provides a tool that will add the need schema for pins to the Directory Server,
and generate the pins for each user.
To set up pin based authentication you do the following:
•
Use the pin tool to add schema needed for pins, add pins to the user entries in
your directory, and then distribute the pins to your users. See “Creating Pins,”
on page 394.
•
Set any policies for certificate extensions, or for constraints on certificates, see
Chapter 11, “Policies” for information about policies. Alternatively, you can
enroll users through the certificate profile functionality setting policies for
specific certificates in the certificate profile, see Chapter 10, “Certificate
Profiles” for information about policies.
•
Create an instance of the
UidPwdPinDirAuth
Authentication plug-in module
and configure the instance. See “Setting Up the UidPwdPinDirAuth
Authentication,” on page 395 for details.
•
Customize the HTML enrollment forms. Make sure the proper authentication
method is contained in the form, and do any other customization required.
In the enrollment form you use, be sure to include the following line, and
replace
myAuthMgr
with the name of the authentication instance you added.
<INPUT TYPE="HIDDEN" NAME="authenticator" VALUE="myAuthMgr">
For more information on customizing the enrollment forms, see the CMS
Customization Guide.
•
In the case of certificate profile-based enrollments, customize the enrollment
forms by configuring the inputs in the certificate profile. Make sure you
include the information that will be needed by the plug-in to authenticate the
user. If the default inputs do not contain all of the information that needs to be
collected, you can either create an input that does using the CMS SDK, or
submit a request created with a third-party tool.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...