Role Of Distinguished Names In Certificates - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Add the encoding order to the configuration file.
4.
For example, if you want to specify two encoding values,
UniversalString
UniversalString
configuration file:
X500Name.directoryStringEncodingOrder=PrintableString,
UniversalString
Save your changes and close the file.
5.
To verify that the encoding order are in effect, enroll for a certificate using the manual
6.
enrollment form. Use
Go to the agent interface and approve your request.
7.
When you receive the certificate, use the
8.
the certificate. For details about the
Guide.
The CN component of the subject name should be encoded as a
Repeat Steps 6 through 8 above, but use
9.
The CN component of the subject name should be encoded as a PrintableString.

Role of Distinguished Names in Certificates

In certificates issued by Certificate System, DNs are used to identify the entity that owns the
certificate. In all cases, if you are using Certificate System with a directory, the format of
the DNs in your certificates should match the format of the DNs in your directory. It is not
necessary that the names match exactly; certificate mapping allows the subject DN in a
certificate to be different from the one in the directory.
DNs in End-Entity Certificates
In end-entity certificates issued by Certificate System, DNs are used to identify the end
entity that owns the certified key pair. The end entity is one of the following:
The individual who owns the certified key pair (for personal or client certificates—to
form this type of DN, use the
CN=<user's_full_name>, OU=<user's_division_name>,
O=<company_name>, C=<country_name>
, and the encoding order is
next, you would add the following line at the end of the
for CN.
"John_Doe"
dumpasn1
dumpasn1
"John Smith
component to specify the user's full name:
CN
DNs in Certificate System
PrintableString
first and
PrintableString
tool to examine the encoding of
tool, see CS Command-Line Tools
UniversalString
for CN this time.
Appendix I
Distinguished Names
and
.
763

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents