Bind Dn; Directory Authentication Method; Updating Certificates And Crls In A Directory - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

15.10.3. Bind DN

The Certificate Manager accesses the Directory Server using a DN that has read-write permissions to
the directory. To publish certificates and CRLs to the directory, the Certificate Manager needs to use
a directory user entry that has write access to the directory. This enables the Certificate Manager to
modify the user entries with certificate-related information and the CA entry with CA's certificate and
CRL related information.
This entry can be either of the following:
• An existing DN that has write access, such as the Directory Manager.
• A new user which is granted write access. The entry can be identified by the Certificate
Manager's DN, such as cn=testCA, ou=Research Dept, o=Example Corporation,
st=California, c=US.
NOTE
Carefully consider what privileges are given to this user. This user can be restricted
in what it can write to the directory by creating ACLs for the account. For instructions
on giving write access to the Certificate Manager's entry, see the Directory Server
documentation.

15.10.4. Directory Authentication Method

Depending on how the Certificate Manager should authenticate to the directory, set up Directory
Server for one of the following methods of communication:
• Publishing with basic authentication
• Publishing over SSL without client authentication
• Publishing over SSL with client authentication
See the Red Hat Directory Server documentation for instructions on setting up these methods of
communication with the server.

15.11. Updating Certificates and CRLs in a Directory

The Certificate Manager and the publishing directory can become out of sync if certificates are issued
or revoked while the Directory Server is down. Certificates that were issued or revoked need to be
published or unpublished manually when the Directory Server comes back up.
To find certificates that are out of sync with the directory
and revoked or expired certificates that are still in the directory
a record of whether a certificate in its internal database has been published to the directory. If the
Certificate Manager and the publishing directory become out of sync, use the Update Directory option
in the Certificate Manager agent services page to synchronize the publishing directory with the internal
database.
The following choices are available for synchronizing the directory with the internal database:
• Search the internal database for certificates that are out of sync and publish or unpublish.
valid certificates that are not in the directory
the Certificate Manager keeps
Bind DN
361

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents