Configuring Publishing to an LDAP Directory
211
Figure 8.5. Publisher Editor Window
The
host
can be the fully-qualified domain name or an IPv4 or IPv6 address.
5. Set the publisher ID, an alphanumeric string with no spaces like
PublishCertsToOCSP
; the fully-
qualified domain name, such as
ocspResponder.example.com
, and port number of the Online
Certificate Status Manager; and the default path,
/ocsp/ee/ocsp/addCRL
.
After configuring the publisher, configure the rules for the published certificates and CRLs, as
described in
Section 8.2.4, “Creating Rules”
.
8.2.3. Configuring Publishing to an LDAP Directory
Configuring LDAP publishing is similar to other publishing procedures, with additional steps to
configure the directory:
1. Configure the Directory Server to which certificates will be published. Certain attributes have to be
added to entries and bind identities and authentication methods have to be configured.
2. Configure a publisher for each type of object published: CA certificates, cross-pair certificates,
CRLs, and user certificates. The publisher declares in which attribute to store the object. The
attributes set by default are the X.500 standard attributes for storing each object type. This
attribute can be changed in the publisher, but, generally, it's not necessary to change the LDAP
publishers.
3. Set up mappers to enable an entry's DN to be derived from the certificate's subject name.
This generally does not need set for CA certificates, CRLs, and user certificates. There can be
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...