
Automated Enrollment
Chapter 10
Authentication
381
ldap.ldapauth.bindDN.
Specifies the user entry to bind as when removing PINs from
the authentication directory. You need to specify this parameter only if you’ve selected
removePin
. It is recommended that you create and use a separate user entry that has
permission to modify only the PIN attribute in the directory. For example, don’t use the
directory manager’s entry as it has privileges to modify the entire directory content.
password.
Specifies the password associated with the DN specified by the
ldap.ldapauthbindDN
parameter. when you save your changes, the server stores
the password in the single sign-on password cache and uses it for subsequent start
ups.You need to specify this parameter only if you’ve selected
removePin
.
ldap.ldapauth.clientCertNickname.
Specifies the nickname of the certificate to be
used for SSL client authentication to the authentication directory in order to remove
PINs. Make sure that the certificate is valid and has been signed by a CA that is trusted
in the authentication directory’s certificate database, and that the authentication
directory’s
certmap.conf
file has been configured to correctly map the certificate to
a DN in the directory. (This is needed for PIN removal only.)
ldap.ldapauth.authtype.
Specifies the authentication type—basic authentication or
SSL client authentication—required in order to remove PINs from the authentication
directory.
❍
BasicAuth
specifies basic authentication. If you choose this option, be sure to
enter the correct values for
ldap.ldapauth.bindDN
and
password
parameters;
the server uses the DN from the
ldap.ldapauth.bindDN
attribute to bind to the
directory (default).
❍
SslClientAuth
specifies SSL client authentication. If you choose this option,
be sure to set the value of the
ldap.ldapconn.secureConn
parameter to
true
and the value of the
ldap.ldapauth.clientCertNickname
parameter to the
nickname of the certificate to be used for SSL client authentication.
ldap.basedn.
Specifies the base DN for searching the authentication directory—the
server uses the value of the
uid
field from the HTTP input (what a user enters in the
enrollment from) and the base DN to construct an LDAP search filter.
ldap.minConns.
Specifies the minimum number of connections permitted to the
authentication directory.Permissible values:
1
to
3
.
ldap.maxConns.
Specifies the maximum number of connections permitted to the
authentication directory.Permissible values:
3
to
10
.
7.
Click OK. The authentication instance is now set up and enabled.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...