
Chapter 4. Certificate Manager
102
Automatic notification can be set up so an email is sent to an agent any time a request appears
in the queue. Also, an automated job can be set to send a list of the contents of the queue to
agents on a preconfigured schedule. See
Chapter 17, Automated Notifications
and
Chapter 18,
Automated Jobs
.
• The automated process, which involves end-entity authentication, processes the certificate
request as soon as the end entity successfully authenticates.
5. The form collects information about the end entity from an LDAP directory when the form is
submitted. For certificate profile-based enrollment, the defaults for the form can be used to collect
the user LDAP ID and password.
6. The certificate profile associated with the form determine aspects of the certificate that is issued.
Depending on the certificate profile, the request is evaluated to determine if the request meets the
constraints set, if the required information is provided, and the contents of the new certificate.
7. The form can also request that the user export the private encryption key. If the DRM subsystem is
set up with this CA, the end entity's key is requested, and an archival request is sent to the DRM.
This process generally requires no interaction from the end entity.
8. The certificate request is either rejected because it did not meet the certificate profile or
authentication requirements, or a certificate is issued.
9. The certificate is delivered to the end entity.
• In automated enrollment, the certificate is delivered to the user immediately. Since the
enrollment is normally through an HTML page, the certificate is returned as a response on
another HTML page.
• In agent-approved enrollment, the certificate can be retrieved by serial number or request Id in
the end-entity interface.
• If the notification feature is set up, the link where the certificate can be obtained is sent to the
end user.
10. An automatic notice can be sent to the end entity when the certificate is issued or rejected.
11. The new certificate is stored in the Certificate Manager's internal database.
12. If publishing is set up for the Certificate Manager, the certificate is published to a file or an LDAP
directory.
13. The internal OCSP service checks the status of certificates in the internal database when a
certificate status request is received.
The end-entity interface has a search form for certificates that have been issued and for the CA
certificate chain.
4.1.2. Revocation
End entities can request that their own certificates be revoked. When an end entity makes the request,
the certificate has to be presented to the CA. If the certificate and the keys are available, the request is
processed and sent to the Certificate Manager, and the certificate is revoked. The Certificate Manager
marks the certificate as revoked in its database and adds it to any applicable CRLs.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...