Chapter 15. Authentication for Enrolling Certificates
344
If the authentication method is automated, the end entity submits the request along with required
information to authenticate the user, such as an LDAP username and password. When the user is
successfully authenticated, the request is processed without being sent to an agent's queue. If the
request passes the certificate profile configuration of the Certificate Manager, the certificate is issued
and stored in the internal database. It is delivered to the end entity immediately through the HTML
forms.
NOTE
An email can be automatically sent to an end entity when the certificate is issued for any
authentication method by configuring automated notifications. See
Chapter 17, Automated
Notifications
for more information on notifications.
15.2. Agent-Approved Enrollment
The Certificate Manager is initially configured for agent-approved enrollment. An end entity makes
a request which is sent to the agent queue for an agent's approval. An agent can modify request,
change the status of the request, reject the request, or approve the request. Once the request is
approved, the signed request is sent to the Certificate Manager for processing. The Certificate
Manager processes the request and issues the certificate.
The agent-approved enrollment method is not configurable. If a Certificate Manager is not configured
for any other enrollment method, the server automatically sends all certificate-related requests to
a queue where they await agent approval. This ensures that all requests that lack authentication
credentials are sent to the request queue for agent approval.
15.2.1. Configuring Agent-Approved Enrollment
To configure agent-approved enrollment, do the following:
1. Set up the certificate profiles to use to enroll users, such as specifying agent-approved enrollment
and setting policies for specific certificates in the certificate profile. See
Chapter 12, Certificate
Profiles
for more information about profiles.
2. Customize the HTML enrollment forms. For certificate profile-based enrollment, configure inputs
that are used to generate the HTML enrollment form dynamically.
15.3. Automated Enrollment
In automated enrollment, an end-entity enrollment request is processed as soon as the user
successfully authenticates by the method set in the authentication plug-in module; no agent approval
is necessary. The following authentication plug-in modules are provided:
•
Directory-based enrollment.
End entities are authenticated against an LDAP directory using their
user ID and password or their DN and password. See
Section 15.3.1, “Setting up Directory-Based
Authentication”
.
•
PIN-based enrollment.
End entities are authenticated against an LDAP directory using their user
ID, password, and a PIN set in their directory entry. See
Section 15.3.2, “Setting up PIN-based
Enrollment”
.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...