Setting up Certificate Profiles
273
13.3. Setting up Certificate Profiles
Certificate profiles are managed by changing the existing certificate profiles, deleting an existing
certificate profile, or adding another certificate profile. Maintaining certificate profiles includes the
following process:
• Deciding which certificate profiles are needed in the PKI. There should be at least one profile
for each type of certificate issued. There can be more than one certificate profile for each type
of certificate to set different authentication methods or different defaults and constraints for a
particular type of certificate type. Any certificate profile available in the administrative interface can
be approved by an agent and then used by an end entity to enroll.
• Deleting any certificate profiles that will not be used.
• Creating custom certificate profiles.
• Modifying the existing certificate profiles and any custom certificate profiles.
• Changing the defaults set up in the certificate profile, the values of the parameters set in the
defaults, or the constraints that control the certificate content.
• Changing the constraints set up by changing the value of the parameters.
• Changing the authentication method.
• Changing the inputs by adding or deleting inputs in the certificate profile, which control the fields
on the input page.
• Adding or deleting the output.
•
Section 13.3.1, “Modifying Certificate Profiles through the CA Console”
•
Section 13.3.2, “Modifying Certificate Profiles through the Command Line”
•
Section 13.3.4, “Customizing the Enrollment Form”
13.3.1. Modifying Certificate Profiles through the CA Console
An administrator cannot edit any certificate profile that has been approved by an agent. The agent
must disapprove or disable the certificate profile before the administrator can edit that certificate
profile.
Add a certificate profile and modify an existing certificate profile by doing the following:
1. Log in to the Certificate System CA subsystem console.
pkiconsole https://
host:SSLport
/ca
2. In the
Configuration
tab, select
Certificate Manager
, and then select
Certificate Profiles
.
The
Certificate Profile Instances Management
tab, which lists configured certificate profiles,
opens.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...