Chapter 12. Certificate Profiles
NOTE
The profile instance ID cannot be modified.
Once a certificate profile is enabled by an agent, that certificate profile is marked enabled in the
Certificate Profile Instance Management tab, and the certificate profile cannot be edited in any
way. To edit that certificate profile, an agent must first disable the certificate profile.
11. Delete any certificate profiles that will not be approved by an agent. Any certificate profile that
appears in the Certificate Profile Instance Management tab also appears in the agent services
interface. If a profile has already been enabled, it must be disabled by the agent before it can be
deleted from the profile list.
12.3.2. Modifying Certificate Profiles through the Command Line
The certificate profiles can be modified directly through the command line by modifying the profiles'
configuration files. The certificate profiles have individual configuration files which can be modified
through the command line. Default files exist for the default profiles at installation; when new profiles
are created, new configuration files are also created. The configuration files are stored in the CA
profile directory, instance_directory/profiles/ca/, such as /var/lib/rhpki-ca/profiles/
ca/. The file is named profile_name.cfg. All of the parameters for profile rules set or modified
through the Console, such as defaults, inputs, outputs, and constraints, are written to the profile
configuration file.
NOTE
Restart the server after editing the profile configuration file for the changes to take effect.
Section 12.3.2.1, "Profile Configuration Parameters"
•
Section 12.3.2.2, "Modifying Certificate Extensions through the Command Line"
•
Section 12.3.2.3, "Adding Inputs through the Command Line"
•
12.3.2.1. Profile Configuration Parameters
The configuration files are stored in the CA profile directory, such as /var/lib/rhpki-ca/
profiles/ca/. The file is named profile_name.cfg. All of the parameters for a profile rule -
defaults, inputs, outputs, and constraints - are configured within a single policy set. A policy set for a
profile has the name policyset.policyName.policyNumber. For example:
policyset.cmcUserCertSet.6.constraint.class_id=noConstraintImpl
policyset.cmcUserCertSet.6.constraint.name=No Constraint
policyset.cmcUserCertSet.6.default.class_id=userKeyDefaultImpl
policyset.cmcUserCertSet.6.default.name=User Supplied Key Default
policyset.cmcUserCertSet.6.default.params.userExtOID=2.5.29.15
The common profile configuration parameters are described in
Parameters".
248
Table 12.1, "Profile Configuration File
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers