![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 413](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697413.webp)
CEP Enrollment
Chapter
9
Authentication
413
Setting Up Automated CEP Enrollment
You can configure the Certificate Manager to use either the challenge password or
the subject name (all or a part of it) as an authentication token during a CEP
enrollment, thus enabling users to get router certificates without any action on the
part of the Certificate Manager agent.
CMS does not install an authentication module for CEP enrollment, but does
provide a sample along with the CMS SDK that you can register and then
configure, named
FlatFileAuth
.
This plug-in uses a file, called an authentication token, containing information that
will be provided by the enrollee to uniquely identify it, and the password created
for the enrollee that they present during enrollment to authenticate themselves.
To set this up, you must create the authentication-token file, and register and
configure the plug-in. See “Authentication-Token File,” on page 413 and “Setting
Up the CEP Plug-In,” on page 414.
Authentication-Token File
You create a text file with CEP-enrollee information that is used by the plug-in to
authenticate the entity. The format of the authentication-token file is as follows:
<attribute>: <value>
<attribute>: <value>
...
<attribute>: <value>
<attribute>: <value>
Each enrolling user is represented by a sequence of attribute-value pairs,
terminated by a blank line or end-of-file (EOF). The attributes can be any part of the
subject name from the request, for example
SERIALNUMBER
,
UNSTRUCTUREDADDRESS
,
CN
,
OU
,
UID
, or the challenge password (
pwd
). These attributes are described as
follows:
UNSTRUCTUREDNAME
Specifies the DNS name of the router (for example,
router32.example.com
). This is always specified in the
request.
UNSTRUCTUREDADDRESS
Specifies the IP address of the router (for example,
101.22.33.124
). This may not be in the request—a user
may not want to include this in the subject name of the
router certificate, and hence choose not to specify one
during enrollment.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...