![Red Hat CERTIFICATE 7.1 ADMINISTRATOR Скачать руководство пользователя страница 121](http://html.mh-extra.com/html/red-hat/certificate-7-1-administrator/certificate-7-1-administrator_administrators-manual_1427416121.webp)
Configuring the Certificate Manager
Chapter 3
Certificate Manager
121
1.
In the CS window for the Certificate Manager issuing the certificates, select the
Configuration tab.
2.
Select Authentication in the navigation tree.
The right pane shows the Authentication Instance tab listing currently configured
authentication instances.
3.
Click Add.
The Select Authentication Plug-in Implementation window appears.
4.
Select the
CMCAuth
plug-in module.
5.
Click Next.
The Authentication Instance Editor window appears.
6.
If you don’t want to use the default instance name, in the Authentication Instance ID
field, type a unique name for this instance that will help you identify it. If you chose to
use a different name, be sure to edit the default name in the enrollment forms.
There are no configuration options for this plug-in; it simply enables this functionality.
7.
Click OK. The authentication instance is now set up and enabled.
Setting Up the Server for Multiple Requests in a Full
CMC Request
CMC supports multiple CRMF or PKCS #10 requests in a single full CMC request. If the
numRequests
parameter in the .cfg file > 1, you need to modify the server’s certificate
profile. To do so, follow these steps:
1.
By default, the servlet processing a full CMC request uses the profile
caFullCMCUserCert
. Currently, this profile handles a single request only. If you
expect to send full CMC requests that contain
n
requests, make sure you have
n
number
of setIDs on the
policyset.list
line in
caFullCMCUserCert.cfg
, located in
<server_root>/cert-<instanceid>/profiles/ca/
. You also need to specify
new policy rules for each newly created policy setID.
2.
To use the new profile instead of the default one, you must modify
web.xml
, located in
<server_root>/cert-<instanceid>/webapps/ee/WEB-INF/
. Locate the
servlet (by default,
/ca/profileSubmitCMCFull
) used to process the full CMC
request, and change the value for the parameter
profileID
to the name of your new
profile.
Note:
For information on creating a new profile, see Chapter 11, “Certificate Profiles.”
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...