Chapter 2. Making Rules for Issuing Certificates
36
a profile has already been enabled, it must be disabled by the agent before it can be deleted from the
profile list.
NOTE
Restart the server after editing the profile configuration file for the changes to take effect.
2.2.3. Creating and Editing Certificate Profiles through the
Command Line
The certificate profiles can be modified directly through the command line by modifying the profiles'
configuration files. The certificate profiles have individual configuration files which can be modified
through the command line. Default files exist for the default profiles at installation; when new profiles
are created, new configuration files are also created. The configuration files are stored in the CA
profile directory,
instance_directory
/profiles/ca/
, such as
/var/lib/pki-ca/profiles/ca/
.
The file is named
profile_name
.cfg
. All of the parameters for profile rules set or modified through the
Console, such as defaults, inputs, outputs, and constraints, are written to the profile configuration file.
The enrollment profiles for system certificates are located in the
/var/lib/
subsystem_name
/conf
directory with the name *
.profile
.
NOTE
Restart the server after editing the profile configuration file for the changes to take effect.
•
Section 2.2.3.1, “Profile Configuration Parameters”
•
Section 2.2.3.2, “Modifying Certificate Extensions through the Command Line”
•
Section 2.2.3.3, “Adding Inputs through the Command Line”
2.2.3.1. Profile Configuration Parameters
The configuration files are stored in the CA profile directory, such as
/var/lib/pki-ca/profiles/
ca/
. The file is named
profile_name
.cfg
. All of the parameters for a profile rule - defaults, inputs,
outputs, and constraints - are configured within a single policy set. A policy set for a profile has the
name
policyset.
policyName.policyNumber
. For example:
policyset.cmcUserCertSet.6.constraint.class_id=noConstraintImpl
policyset.cmcUserCertSet.6.constraint.name=No Constraint
policyset.cmcUserCertSet.6.default.class_id=userExtensionDefaultImpl
policyset.cmcUserCertSet.6.default.name=User Supplied Key Default
policyset.cmcUserCertSet.6.default.params.userExtOID=2.5.29.15
The common profile configuration parameters are described in
Table 2.1, “Profile Configuration File
Parameters”
.
There is only one policy set processed for the profile, except for dual key pairs when two policy sets
are processed. The server evaluates each policy set for each request it receives. When a single
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...