Issuing Cross-Pair Certificates; Importing Cross-Pair Certificates; Publishing Cross-Pair Certificates - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Federal Bridge CA

Issuing Cross-Pair Certificates

The policy feature allows you to configure the policy
provide
other necessary policies for this kind of certificate. You would then associate an end-entity
enrollment page, customized to enroll for cross-pair certificates, providing the hidden value
certType==fbca
You can also use the Certificate Setup wizard to create a cross-pair certificate request that
can be sent to another CA. You might create this request and then paste it into an existing
end-entity interface enrollment page, or a customized page that requires a request rather
than forming the request from that page.
See Chapter 12, "Policies" for more information about policies.

Importing Cross-Pair Certificates

CS provides the capability to import the cross-pair certificates from each of the CAs. You
use the Certificate Setup wizard to import both certificates. When both certificates have
been imported into the database, a
database. The original certificates are deleted once the
formed.
You can search for and view a
following LDAP search command:
./ldapsearch -h <yourHostName> -p <yourCAInternalDBPort >
-b "o=netscapeCertificateServer" -D "cn=Directory Manager"
-w <DirectoryManagerPassword> "cn=crossCerts"
See "Certificate Setup Wizard," on page 289" for more information about the Certificate
Setup Wizard.

Publishing Cross-Pair Certificates

You can publish cross-pair certificates (as a
directory or to a file. When you set up publishing, you can specify cross-pair certificates in
the rule you set up for this type of certificate by selecting
Rule Editor window. CS provides a rule called
publishing cross-pair certificates.
126
Red Hat Certificate System Administrator's Guide • September 2005
HTTP_PARAMS.certType==fbca
, thus activating policies associated with FBCA to this request.
crossCertificatePair
CertificatePoliciesExt
as the predicate value, and then set up any
crossCertificatePair is
crossCertificatePair
crossCertificatePair
LDAPXCertRule
formed and stored in the
in the database using the
) to either an LDAP
in the type field of the
xcerts
that is pre configured for
and
is

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents