Configuring Rule Instances
373
Parameter
Description
where
org
and
country
are replaced with values
from the DN in the certificate.
If the
dnComps
field is empty, the server checks
the
baseDN
field and searches the directory tree
specified by that DN for entries matching the filter
specified by
filterComps
parameter values.
The permissible values are valid DN components
or attributes separated by commas.
filterComps
Specifies components the Certificate Manager
should use to filter entries from the search result.
The server uses the
filterComps
values to
form an LDAP search filter for the subtree. The
server constructs the filter by gathering values for
these attributes from the certificate subject name;
it uses the filter to search for and match entries in
the LDAP directory.
If the server finds more than one entry in the
directory that matches the information gathered
from the certificate, the search is successful, and
the server optionally performs a verification. For
example, if
filterComps
is set to use the email
and user ID attributes (
filterComps=e,uid
),
the server searches the directory for an entry
whose values for email and user ID match the
information gathered from the certificate.
The permissible values are valid directory
attributes in the certificate DN separated by
commas. The attribute names for the filters need
to be attribute names from the certificate, not
from ones in the LDAP directory. For example,
most certificates have an
e
attribute for the user's
email address; LDAP calls that attribute
.
Table 15.13. LdapDNCompsMap Configuration Parameters
15.13.3. Configuring Rule Instances
This section discusses the rule instances that have been set.
15.13.3.1. LdapCaCertRule
The
LdapCaCertRule
can be used to publish CA certificates to an LDAP directory.
Parameter
Value
Description
type
cacert
Specifies the type of certificate that will be published.
predicate
Specifies a predicate for the publisher.
enable
yes
Enables the rule.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...