Customizing the Subject DN in a Certificate Request Issued by an RA
67
X500Name.dirEncodingOrder=Printable,BMPString
To change the
DirectoryString
encoding, do the following:
1. Stop the Certificate Manager.
service pki-ca stop
2. Open the
/var/lib/pki-ca/conf/
directory.
3. Open the
CS.cfg
configuration file.
4. Add the encoding order to the configuration file.
For example, to specify two encoding values,
PrintableString
and
UniversalString
, and
the encoding order is
PrintableString
first and
UniversalString
next, add the following
line at the end of the configuration file:
X500Name.directoryStringEncodingOrder=PrintableString, UniversalString
5. Save the changes, and close the file.
6. Start the Certificate Manager.
service pki-ca start
7. To verify that the encoding orders are in effect, enroll for a certificate using the manual enrollment
form. Use
John_Doe
for the
cn
.
8. Open the agent services page, and approve the request.
9. When the certificate is issued, use the
dumpasn1
tool to examine the encoding of the certificate.
The
dumpasn1
tool can be downloaded at
http://fedoraproject.org/extras/4/i386/repodata/
repoview/dumpasn1-0-20050404-1.fc4.html
.
The
cn
component of the subject name should be encoded as a
UniversalString
.
10. Create and submit a new request using
John Smith
for the
cn
.
The
cn
component of the subject name should be encoded as a
PrintableString
.
2.7.3. Customizing the Subject DN in a Certificate Request Issued
by an RA
By default, the DN is taken from the input provided by the user on the User Enrollment page,
specifically "UID" and "Your Email." For example, "UID=yourUID, [email protected]". You
can customize the DN by editing the
user.vm
file for the RA.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...