Chapter 16. Authentication for Enrolling Certificates
386
2. Create a certificate request using the
certutil
tool.
3. Copy the PKCS #10 ASCII output to a text file.
4. Run the CMCEnroll utility.
For example, if the input file called
request34.txt
, the agent certificate is stored in the
directory
/var/lib/rhpki-ca/alias
, the certificate common name of the agent certificate
is
CertificateManagerAgentsCert
, and the password for the certificate database is
1234pass
, the command is as follows:
CMCEnroll -d "/var/lib/rhpki-ca/alias" -n "CertificateManagerAgentsCert"
-r /export/requests/request34.txt -p 1234pass
The output of this command is stored in a file with the same filename with
.out
appended to the
filename.
5. Submit the signed certificate through the end-entities page.
a. Open the end-entities page.
https://server.example.com:9443/ca/ee/ca
b. Select the CMC enrollment form from the list of certificate profiles.
c. Paste the content of the output file into the
Certificate Request
text area of this form.
d. Remove
-----BEGIN NEW CERTIFICATE REQUEST-----
and
----END NEW
CERTIFICATE REQUEST-----
from the pasted content.
e. Fill in the contact information, and submit the form.
6. The certificate is immediately processed and returned.
7. Use the agent page to search for the new certificate.
16.5. Certificate-Based Enrollment
NOTE
This feature is supported only in legacy enrollment. Certificate System supports certificate-
based enrollment for browser certificates. End users can use preissued certificates to
authenticate to the server in order to enroll for certificates.
Certificate-based enrollment is useful in two common deployment scenarios:
• A client is deployed that can generate dual key pairs. Dual certificates, one for signing and one
for encrypting data, need to issued to the users. Additionally, users should be able to put their key
materials only on hardware tokens.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...