
Chapter 16. User and Group Authorization
362
1. Log into the administrative console for the subsystem to which the trusted manager is being
added.
pkiconsole https://
host:SSLport/subsystemType
2. In the
Configuration
tab, select
Users and Groups
. Click
Add
.
3. Fill in the identifying information.
The information is to help keep track of the trusted manager entry; the subsystem never uses it.
The subsystem relies solely on the trusted manager's SSL client certificate for authentication.
Figure 16.2. Creating the Trusted Manager Account
The full name must be the fully qualified host name of the Certificate Manager. The group must be
set to
Trusted Managers
do that the CA has trusted manager privileges.
4. Store the Certificate Manager's SSL client certificate in the internal database of the subsystem.
a. In the
Users
tab, select the trusted manager entry, and click
Certificates
.
b. Click
Import
.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...