Setting Up Publishing
622
Netscape Certificate Management System Administrator’s Guide • June 2003
4.
For LDAP publishing, you need to set up Mappers to enable an entries’ DN to
be derived from the certificate’s subject name. Generally, you will need to set
one up for the CA certificate, CRLs and for user certificates. You can also set
more than one up for a particular type. You might do this, for example, if you
have two sets of users from different divisions of your company who are
located in different parts of the directory tree. You might create one Mapper for
each of the groups that specifies a different branch of the tree.
For complete details about setting up Mappers, see “Configuring Mappers,” on
page 632.
5.
You set up Rules to determine what exactly gets published where. Rules work
independently, not in tandem. A certificate or CRL that is being published is
matched against every rule. Any rule to which it matches is activated. In this
way, the same certificate can be published to a file and to an LDAP directory
by matching a file-based rule and matching a directory-based rule.
You can set up rules for each object type: CA certificate, CRL, user certificate,
and cross-pair certificate, or you can even further divide the rules so that you
have different rules for different kinds of certificates, or different kinds of
CRLs.
The rule first determines if the object meets the rule, and then where it is to be
published. Determining if the object meets the rule is done by matching the
type and predicate set up in the rule with the object itself. Determining where
matching objects are published is determined by the Publisher and Mapper
that is associated with this rule.
For complete details about setting up Rules, see “Modifying Publishing Rules
for Certificates and CRLs,” on page 644.
6.
If you are publishing CRLs, you must set up CRLs before you can publish
them. See Chapter 14, “Revocation and CRLs” for complete details.
7.
For LDAP publishing, you need to configure the Directory Server you will be
publishing to. See “Configuring the Directory for LDAP Publishing,” on page
655 for details.
8.
Enable Publishing. You should enable publishing after setting up Publishers,
Mappers and Rules. Once it is enabled, the server will start publishing. If you
have not finished setting up, publishing may not work correctly, or at all.
For complete details, see “Enabling Publishing,” on page 651.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...