Chapter 4. Requesting, Enrolling, and Managing Certificates
92
email=true
ssl_client=true
digital_signature=true
non_repudiation=true
key_encipherment=true
challengePassword=secret
confirmChallengePassword=secret
[email protected]
csrRequestorPhone=9195550000
csrRequestorComments=
CRMFRequest=iJIaifasiuas90AEIFJHui
submit=Submit
subject=CN=John%20Smith,O=Example%20Corp.
certType=client
certPrettyPrint=false
csrRequestorName=
email=false
ssl_client=true
digital_signature=false
non_repudiation=true
key_encipherment=true
challengePassword=
confirmChallengePassword=
[email protected]
csrRequestorPhone=
csrRequestorComments=
CRMFRequest=iJIaifasiuas90AEIFJHui
submit=Submit
subject=CN=Mark%20Jones,O=Example%20Corp.
certType=client
certPrettyPrint=true
Example 4.1. Bulk Issuance POST File
4.5.2. Running the Bulk Issuance Command
The POST file is submitted directly to the CA using the
bulkissuance
command, not through the
web services pages or console.
The person performing the bulk issuance authenticates to the CA using his agent's certificate, which is
also used to approve the certificates automatically. The
bulkissuance
command passes the agent
certificate nickname, the HTML POST input file, and the URL of the CA's bulk issuance interface:
bulkissuance -n
rsa_nickname
-f
inputFile
hostname:port
/ca/bulkissuance
For example:
bulkissuance -n "CN=John Smith pki-ca Agent,O=Example Domain" -f /home/jsmith/bulkissuance.txt
server.example.com:9443/ca/bulkissuance
Because the certificate request is automatically approved by the agent submitting the bulk issuance
request, the newly-issued certificates are immediately ready to be retrieved from the CA and installed
on the HSM or server.
The
bulkissuance
tool is also described in the
Certificate System Command-Line Tools Guide
.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...