
Constraints-Specific Policy Module Reference
476
Red Hat Certificate System Administrator’s Guide • September 2005
In the case of multi-valued attributes, the request will be accepted if any of the values
matches the specified value; comparisons are case sensitive.
Unlike some of the other policy modules, CS does not create an instance of the attribute
present constraints policy during installation.
Table 12-3 describes the configuration parameters of the
AttributePresentConstraints
policy.
Table 12-3
AttributePresentConstraints Configuration Parameters
Parameter
Description
enable
Specifies whether the rule is enabled or disabled. Select to enable (default), deselect to
disable.
predicate
Specifies the predicate expression for this rule. If you want this rule to be applied to all
certificate requests, leave the field blank (default). To form a predicate expression, see “Using
Predicates in Policy Rules” on page 465.
ldap.ldapconn.
host
Specifies the host name of the LDAP directory to connect to.
Permissible values: The name must be fully-qualified host name in the
<machine_name>.<your_domain>.<domain>
form.
Example:
corpDirectory.example.com
ldap.ldapconn.
port
Specifies the TCP/IP port at which the LDAP directory listens to requests from
CS
.
Permissible values: Any valid port number. The default is 389; use 636 if the directory is
configured for SSL-enabled communication.
ldap.ldapconn.
secureConn
Specifies the type—SSL or non-SSL—of the port at which the LDAP directory listens to
requests from
CS
. Select for SSL, deselect for non-SSL.
ldap.ldapconn.
version
Specifies the LDAP protocol version:
•
2
specifies LDAP version 2. If your directory is based on Red Hat Directory Server 1.x,
choose
2
.
•
3
specifies LDAP version 3. For Directory Server versions 3.x and later, choose
3
(default).
ldap.ldapauth.
bindDN
Specifies the user entry to bind as for checking the attribute in the LDAP directory.
Example:
CN=pinmanager
password
Specifies the password associated with the DN specified by the
ldap.ldapauth.bindDN
parameter.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...