Automated Enrollment
Chapter
9
Authentication
397
ldap.ldapconn.secureConn.
Specifies the type—SSL or non-SSL—of the port
on which the authentication directory listens to requests from CMS. Select if
this is an SSL port, deselect if this is a non-SSL port.
ldap.ldapconn.version.
Specifies the LDAP protocol version.
2
specifies LDAP
version 2. If your authentication directory is based on Netscape Directory
Server 1.x, choose
2
.
3
specifies LDAP version 3. For Directory Server versions
3.x and later, choose
3
(default).
ldap.ldapauth.bindDN.
Specifies the user entry to bind as when removing
PINs from the authentication directory. You need to specify this parameter
only if you’ve selected
removePin
. It is recommended that you create and use a
separate user entry that has permission to modify only the PIN attribute in the
directory. For example, don’t use the directory manager’s entry as it has
privileges to modify the entire directory content.
password.
Specifies the password associated with the DN specified by the
ldap.ldapauthbindDN
parameter. when you save your changes, the server
stores the password in the single sign-on password cache and uses it for
subsequent start ups.You need to specify this parameter only if you’ve selected
removePin
.
ldap.ldapauth.clientCertNickname.
Specifies the nickname of the certificate to
be used for SSL client authentication to the authentication directory in order to
remove PINs. Make sure that the certificate is valid and has been signed by a
CA that is trusted in the authentication directory’s certificate database, and
that the authentication directory’s
certmap.conf
file has been configured to
correctly map the certificate to a DN in the directory. (This is needed for PIN
removal only.)
ldap.ldapauth.authtype.
Specifies the authentication type—basic
authentication or SSL client authentication—required in order to remove PINs
from the authentication directory.
❍
BasicAuth
specifies basic authentication. If you choose this option, be
sure to enter the correct values for
ldap.ldapauth.bindDN
and
password
parameters; the server uses the DN from the
ldap.ldapauth.bindDN
attribute to bind to the directory (default).
❍
SslClientAuth
specifies SSL client authentication. If you choose this
option, be sure to set the value of the
ldap.ldapconn.secureConn
parameter to
true
and the value of the
ldap.ldapauth.clientCertNickname
parameter to the nickname of the
certificate to be used for SSL client authentication.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...