
Configuring the Directory for LDAP Publishing
Chapter 16
Publishing
633
•
Bind DN
•
Directory Authentication Method
Schema
For a Certificate Manager to publish certificates and CRLs to a directory, it must be
configured with specific attributes and object classes. This section discusses those basic
schema requirements.
Required Schema for Publishing End-Entity Certificates
The Certificate Manager publishes an end entity’s certificate to the
userCertificate;binary
attribute within the end entity’s or subject’s directory object.
This attribute is multivalued; each value is a DER encoded binary X.509 certificate. The
LDAP object class named
inetOrgPerson
allows this attribute. This object class is
supported by Directory Server versions 1.0, 3.x, 4.x, and later. The mix-in object class
named
strongAuthenticationUser
allows this attribute and can be combined with any
other object class to allow certificate publication to that object. Note that the Certificate
Manager does not automatically add this object class to the schema table of the
corresponding Directory Server while publishing or unpublishing end-entity certificates. If
the directory object that it finds does not allow the
userCertificate;binary
attribute,
the addition or removal of that specific certificate fails.
If you have created user entries as
inetOrgPerson
, the
userCertificate;binary
attribute already exists in the directory. Otherwise, you must add the
userCertificate;binary
attribute to your directory’s schema table. For information on
modifying directory schema, check the Directory Server documentation.
Required Schema for Publishing the CA Certificate
The Certificate Manager publishes its own CA certificate in the
caCertificate;binary
attribute of the CA’s directory object when the server is started; this is the object that
corresponds to the Certificate Manager’s issuer name. This is a required attribute of the
certificationAuthority
object class. Note that the Certificate Manager will add this
object class to the directory entry for the CA, provided that it finds the CA’s directory entry.
Required Schema for Publishing CRLs
The Certificate Manager publishes the updated CRL to the CA’s directory object under this
attribute:
certificateRevocationList;binary
.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...