Requesting Certificates
197
The authentication process is determined by the certificate profiles that are associated with the
enrollment forms used. This can be done automatically by the server applying preset criteria or by
manual approval from an agent. Once the request is approved, it is available through the CA's end-
entities page for the entity to retrieve.
NOTE
For more information on authentication for enrollment, see
Chapter 15, Authentication for
Enrolling Certificates
and
Chapter 12, Certificate Profiles
.
•
Section 10.2.1, “Requesting Certificates”
•
Section 10.2.2, “Submitting Certificate Requests”
•
Section 10.2.3, “Retrieving Certificates from the End-Entities Page”
10.2.1. Requesting Certificates
The different methods of requesting certificates allow different types of certificates which can be
requested. End users can request client certificates, either agent or user certificates for the Certificate
System or for use with other applications. Administrators can request certificates for servers and
Certificate System instances.
•
End-Entities Page: User and Agent Certificates
The end-entities pages can be accessed by any user. Those enrollment forms can be used to
request user and agent certificates. See
Section 10.2.1.1, “Requesting a User or Agent Certificate
through the End-Entities Page”
.
•
Certificate Wizard: Server and Subsystem Certificates
The administrative console can only be accessed by administrators. The Console can be used
to create requests for CA, OCSP, and CRL signing certificates; SSL server certificates; client
certificates; and DRM transport certificates. See
Section 10.2.1.2, “Requesting a Subsystem,
Server, or Signing Certificate through the Console”
.
•
certutil: All Certificates
The
certutil
utility can be used by administrators or users to generate any certificate.
10.2.1.1. Requesting a User or Agent Certificate through the End-Entities
Page
End entities can use the HTML enrollment forms on the Certificate Management end-entities page
to create user certificates for email and SSL authentication. Other enrollment forms are available for
adding certificates to tokens and signing files. For more information about the end-entities enrollment
forms, see the
Certificate System Agent's Guide
.
The following forms are used to create user certificates:
• Manual User Dual-Use Certificate Enrollment
• Manual User Signing and Encryption Certificates Enrollment
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...