Configuring a Registration Manager
Agent-Approved Enrollment
The Registration Manager is enabled by default for agent-approved enrollment. The
agent-approved enrollment form is used to enroll end entities whose request is sent to the
agent services interface for processing. If you are using the certificate profile feature, an
agent-approved enrollment is associated with any certificate profile that does not declare an
authentication method. Agent-approved certificate profile enrollments are also sent to the
agent services interface for processing.
If you use an agent-approved enrollment process, you can use the agent services interface
forms that are provided, or you can customize those forms to change the look and feel, or to
change some of the default functionality provided in the forms. See the Red Hat Certificate
System Customization Guide for details.
Automated Enrollment
You set up automated enrollment by configuring instances of the authentication plug-ins.
The plug-ins allow you to set up the kind of authentication you will use for enrollment. All
of the authentication plug-ins also enable an automated enrollment when they are enabled.
You can enable one of the authentication plug-ins, and configure it to be able to
authenticate.
Once you have set up an authentication instance, end entities use a form associated with this
method when enrolling. You must provide the necessary fields to collect the information
required for the method of authentication in the form, otherwise you can customize the form
as you like.
The authentication methods that you can configure are:
•
Directory Based Enrollment. End-entities are authenticated against an LDAP
directory using their user ID or DN and password. See "Setting Up Directory Based
Enrollment," on page 374.
•
Pin Based Enrollment. End-entities are authenticated against and LDAP directory
using their user ID, password and a pin given to them. See "Setting Up Pin Based
Enrollment," on page 377.
•
Portal Enrollment. End users are registered into an LDAP directory and issued a
certificate. If user already has an entry in the directory, they are authenticated against
the directory and then issued a certificate. See "Setting Up Portal Enrollment," on page
382.
•
CMC Auth. This plug-in allows you to send agent signed requests and have those
requests processed. See "Setting Up CMC Enrollment," on page 385.
150
Red Hat Certificate System Administrator's Guide • September 2005
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?