Mappers
636
Netscape Certificate Management System Administrator’s Guide • June 2003
If the mapper fails to create a second CA entry, be sure to check the base DN that
the uid uniqueness plug-in is set to (in the
slapd.ldbm.conf
file) and also check if
an entry with the same UID already exists in the directory. If it’s true, adjust the
mapper setting, remove the old CA entry, comment out the plug-in, or create the
entry manually using the Console window.
During installation, the Certificate Manager automatically creates two instances
(called mappers) of the CA certificate mapper module. The mappers are named as
follows:
•
LdapCrlMap
for CRLs (see “LdapCrlMap” on page 637)
•
LdapCaCertMap
for CA certificates (see “LdapCaCertMap” on page 637)
Table 15-8
LdapCaSimpleMap Configuration Parameters
Parameter
Description
createCAEntry
Select if you want the server to create a CA’s entry (default). Deselect
if you don’t want the server to create an entry.
If you select, the Certificate Manager first attempts to create an entry
for the CA in the directory. If the Certificate Manager succeeds in
creating the entry, it then attempts to publish the CA’s certificate to
the entry. If you don’t select, the entry must already be present in
order to publish to it.
dnPattern
Specifies the DN pattern the Certificate Manager should use to
construct the DN in order to search for the CA’s entry in the
publishing directory. The value of
dnPattern
can be a list of AVAs
separated by commas. An AVA can be a variable, such as
CN=$subj.cn
, that the Certificate Manager can derive from the
certificate subject name, or a constant, such as
O=Example
Corporation
.
Note that if your CA certificate does not have the
CN
component in
its subject name, be sure to adjust the CA certificate mapping DN
pattern to reflect the DN of the entry in the directory where the CA
certificate is to be published. For example, if your CA certificate
subject DN is
O=Example Corporation
and the CA’s entry in the
directory is
cn=Certificate Authority, o=Example
Corporation
, the pattern should look like this:
cn=Certificate
Authority, o=$subj.o
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...