![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 792](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697792.webp)
DNs in Certificate Management System
792
Netscape Certificate Management System Administrator’s Guide • June 2003
DNs in End-Entity Certificates
In end-entity certificates issued by Certificate Management System, DNs are used
to identify the end entity that owns the certified key pair. The end entity is one of
the following:
•
The individual who owns the certified key pair (for personal or client
certificates—to form this type of DN, use the
CN
component to specify the
user’s full name:
CN=<user’s_full_name>, OU=<user’s_division_name>,
O=<company_name>, C=<country_name>
For example:
CN=Jane Doe, OU=Human Resources, O=Example Corporation, C=US
•
The server that owns the certified key pair (for SSL server certificates)—to form
this type of DN, use the
CN
component to specify the server’s fully qualified
host name in the form
<machine_name>.<your_domain>.<domain>
:
CN=<host_name>, OU=<division_name>, O=<company_name>,
C=<country_name>
For example:
CN=corpDirectory.example.com, OU=Human Resources, O=Example
Corporation, C=US
When clients such as Netscape Navigator receive a server certificate, they
expect the
CN
component of the certificate’s subject to match the host name in
the URL. If the name in the certificate and the host name of the server do not
match, Navigator notifies the user and gives the user the choice of not
connecting to the server.
For example, if Navigator goes to the URL
https://corpDirectory.example.com
and receives a certificate from the
server, it expects the
CN
component of the certificate’s subject to be
corpDirectory.example.com
. If the
CN
component has a different value (for
example,
corpDir.example.com
), Navigator notifies the user that the
certificate’s subject name does not match the host name in the URL.
DNs in CA Certificates
In CA certificates issued by Certificate Management System (for both root and
subordinate CAs), DNs are used to identify the authority who owns the certified
key pair.
To form this type of distinguished name, use the
CN
component to specify the name
of your CA:
CN=<CA_name>, O=<company_name>, C=<country_name>
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...