![Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Скачать руководство пользователя страница 368](http://html.mh-extra.com/html/red-hat/certificate-system-7-3-administration/certificate-system-7-3-administration_administration-manual_1427433368.webp)
Chapter 15. Publishing
346
Publisher
Description
LdapDeltaCrlPublisher
Used to publish Delta CRLs to the LDAP
directory.
LdapUserCertPublisher
Used to publish all types of end-entity certificates
to the LDAP directory.
LdapCrossCertPairPublisher
Used to publish cross-signed certificates to the
LDAP directory.
Table 15.1. LDAP Publishers
The publishers are enabled and configured using the X.500 standard attributes for storing certificates
and CRLs. The preconfigured publishers do not need modified.
15.4. Configuring Mappers
Mappers are only used with LDAP publishing. Mappers define a relationship between a certificate's
subject name and the DN of the directory entry to which the certificate is published. The Certificate
Manager needs to derive the DN of the entry from the certificate or the certificate request so it can
determine which entry to use. The mapper defines the relationship between the DN for the user entry
and the subject name of the certificate or other input information. This relationship can derive the exact
DN of the entry or set a search for the directory to find the DN of the entry.
During installation, the Certificate Manager automatically creates a set of mappers defining the most
common relationships. The default mappers are listed in
Table 15.2, “Default Mappers”
.
Mapper
Description
LdapUserCertMap
Locates the correct attribute of user entries in the
directory in order to publish user certificates.
LdapCrlMap
Locates the correct attribute of the CA's entry in
the directory in order to publish the CRL.
LdapCaCertMap
Locates the correct attribute of the CA's entry
in the directory in order to publish the CA
certificate.
Table 15.2. Default Mappers
To use the default mappers, configure each of the macros by specifying the DN pattern and whether to
create the CA entry in the directory.
To use other mappers, create and configure an instance of the mapper. For more information see
Section 15.13.2, “Mapper Plug-in Modules ”
.
Modify a mapper by doing the following:
1. Log into the Certificate Manager Console.
pkiconsole https://server.example.com:9443/ca
2. In the
Configuration
tab, select
Certificate Manager
from the navigation tree on the left. Select
Publishing
, and then
Mappers
.
The
Mappers Management
tab, which lists configured mappers, opens on the right.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...