Using Client Certificates
138
Netscape Enterprise Server Administrator’s Guide
Note that the attribute names for the filters need to be attribute names from
the certificate, not from the LDAP directory. For example, some certificates
have an
e
attribute for the user’s email address; whereas LDAP calls that
attribute
.
•
verifycert
tells the server whether it should compare the client’s
certificate with the certificate found in the LDAP directory. It takes two
values: on, and off. You should only use this property if your LDAP
directory contains certificates. This feature is useful to ensure your end-
users have a valid, unrevoked certificate.
•
CmapLdapAttr
is a name for the attribute in the LDAP directory that
contains subject DNs from all certificates belonging to the user. The default
for this property is
certSubjectDN
. This attribute isn’t a standard LDAP
attribute, so to use this property, you have to extend the LDAP schema. For
more information, see
Managing Servers with Netscape Console
.
If this property exists in the
certmap.conf
file, the server searches the
entire LDAP directory for an entry whose attribute (named with this
property) matches the subject’s full DN (taken from the certificate). If the
search doesn’t find any entries, the server retries the search using the
DNComps
and
FilterComps
mappings.
This approach to matching a certificate to an LDAP entry is useful when it’s
difficult to match entries using
DNComps
and
FilterComps
.
Table 5.2 Attributes for x509v3 Certificates
Attribute
Description
c
Country
o
Organization
cn
Common name
l
Location
st
State
ou
Organizational unit
uid
Unix userid
e|mail
Email address
Содержание Netscape Enterprise Server
Страница 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Страница 31: ...Part 1 Server Basics 31 1 Server Basics Introduction to Enterprise Server Administering Enterprise Servers ...
Страница 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Страница 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Страница 64: ...Migrating a Server From a Previous Version 64 Netscape Enterprise Server Administrator s Guide ...
Страница 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Страница 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Страница 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Страница 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Страница 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Страница 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Страница 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Страница 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Страница 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Страница 390: ...Customizing the Web Publisher User Interface 390 Netscape Enterprise Server Administrator s Guide ...
Страница 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Страница 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Страница 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Страница 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Страница 504: ...504 Netscape Enterprise Server Administrator s Guide ...