Creating Custom Renewal Profiles
119
4.7.1.2. Renewal Types in Certificate System
As with any certificate request, a renewal request has to be approved before the CA will issue the new
certificate. Certificate System has three renewal types, depending on the authorization method used to
verify the requester, and any of the three types can be used to renew any kind of certificate:
• Agent-based renewal, where the agent manually approves the request
• Directory-based renewal, where the requester authenticates to an LDAP directory
• Certificate-based renewal, where the certificate stored in the browser's database is used to
authenticate the requester
Authentication is covered in
Chapter 9, Authentication for Enrolling Certificates
.
TIP
Email notifications can be configured for renewal requests; this is described in
Section 10.2, “Setting up Automated Notifications for the CA”
and
Section 11.3.3,
“Configuration Parameters of certRenewalNotifier”
.
4.7.2. Creating Custom Renewal Profiles
Certificate renewal
regenerates a certificate using its original public key, certificate extensions and
constraints, and subject name. A renewed certificate is identical to the original, except that it has a
new expiration date.
When a certificate is renewed, it has to be renewed using a renewal profile that corresponds to
the initial enrollment profile. Certificate System supports renewals both for tokens and for regular
certificates, both through the RA and the CA.
The default configuration profiles cover user certificates and other types of subsystem certificates, as
well as token renewals, but it may be necessary or convenient to create a special renewal profile for a
custom enrollment form.
4.7.2.1. Default Renewal Profiles
Certificate System contains three default renewal profiles for renewing user certificates.
Renewal Profile
Type
caDirUserRenewal.cfg
Directory-based
caManualRenewal.cfg
Agent-based
caSSLClientSelfRenewal.cfg
Certificate-based
Table 4.4. Renewal Profiles
4.7.2.2. Creating an Enrollment Profile
A custom profile is configured the same as described in
Section 2.2, “Setting up Certificate Profiles”
.
There are two settings that must be present in the profile, however, to allow renewal for the certificate:
a setting on whether renewal is allowed and a setting on the time period when renewal is allowed.
The
renewal
parameter sets whether renewal is allowed. This must be
true
:
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...