Publishing Cross-Pair Certificates; Testing Publishing To Files - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

• Authentication. The way the Certificate Manager authenticates to the Directory Server. The
choices are Basic authentication and SSL client authentication.
If the Directory Server is configured for basic authentication or for SSL communication without
client authentication, select Basic authentication and specify values for the Directory
manager DN and password.
If the Directory Server is configured for SSL communication with client authentication, select
SSL client authentication and the Use SSL communication option, and identify the
certificate that the Certificate Manager must use for SSL client authentication to the directory.
The server attempts to connect to the Directory Server. If the information is incorrect, the server
displays an error message.

15.7. Publishing Cross-Pair Certificates

The cross-pair certificates can be published as a crossCertificatePair entry to an LDAP
directory or to a file; this is enabled by default. If this has been disabled, it can be reenabled through
the Certificate Manager Console by doing the following:
1. Open the CA Console
pkiconsole https://server.example.com:9443/ca
2. In the Configuration tab, select the Certificate Manager link in the left pane, then the Publishing
link.
3. Click the Rules link under Publishing. This opens the Rules Management pane on the right.
4. If the rule exists and has been disabled, select the enable checkbox. If the rule has been deleted,
then click Add and create a new rule.
a. Select xcerts from the type drop-down menu.
b. Make sure the enable checkbox is selected.
c. Select LdapCaCertMap from the mapper drop-down menu.
d. Select LdapCrossCertPairPublisher from the publisher drop-down menu.
The mapper and publisher specified in the publishing rule are both listed under Mapper and
Publisher under the Publishing link in the left navigation window of the CA Console. The mapper,
LdapCaCertMap, by default designates that the crossCertificatePair be stored to the
LdapCaSimpleMap LDAP entry. The publisher, LDAPCrossPairPublisher, by default sets the
attribute to store the cross-pair certificate in the CA entry to crossCertificatePair;binary.

15.8. Testing Publishing to Files

To verify that the Certificate Manager is publishing certificates and CRLs correctly to file, do the
following:
1. Open the CA's end-entities page, and request a certificate.
Publishing Cross-Pair Certificates
357

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents