Mapper Plug-In Modules - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

Parameter
path
Table 15.10. OCSPPublisher Parameters

15.13.2. Mapper Plug-in Modules

This section describes the mapper plug-in modules provided for the Certificate Manager. These
modules configure a Certificate Manager to enable and configure specific mapper instances.
The available mapper plug-in modules include the following:
Section 15.13.2.1, "LdapCaSimpleMap"
Section 15.13.2.2, "LdapDNExactMap"
Section 15.13.2.3, "LdapSimpleMap"
Section 15.13.2.4, "LdapSubjAttrMap"
Section 15.13.2.5, "LdapDNCompsMap"
15.13.2.1. LdapCaSimpleMap
The LdapCaSimpleMap plug-in module configures a Certificate Manager to create an entry for the
CA in an LDAP directory automatically and then map the CA's certificate to the directory entry by
formulating the entry's DN from components specified in the certificate request, certificate subject
name, certificate extension, and attribute variable assertion (AVA) constants. For more information on
AVAs, check the directory documentation.
The CA certificate mapper specifies whether to create an entry for the CA, to map the certificate to an
existing entry, or to do both.
If a CA entry already exists in the publishing directory and the value assigned to the dnPattern
parameter of this mapper is changed, but the uid and o attributes are the same, the mapper
fails to create the second CA entry. For example, if the directory already has a CA entry for
uid=CA,ou=Marketing,o=example.com and a mapper is configured to create another CA entry
with uid=CA,ou=Engineering,o=example.com, the operation fails.
The operation may fail because the directory has the UID Uniqueness plug-in set to a specific base
DN. This setting prevents the directory from having two entries with the same UID under that base
DN. In this example, it prevents the directory from having two entries under o=example.com with the
same UID, CA.
If the mapper fails to create a second CA entry, check the base DN to which the UID Uniqueness plug-
in is set, and check if an entry with the same UID already exists in the directory. If necessary, adjust
the mapper setting, remove the old CA entry, comment out the plug-in, or create the entry manually.
During installation, the Certificate Manager automatically creates two instances of the CA certificate
mapper module. The mappers are named as follows:
• LdapCrlMap for CRLs (see
• LdapCaCertMap for CA certificates (see
Description
Specifies the path for publishing the CRL. This
must be the default path, /ocsp/addCRL.
Section 15.13.2.1.2,
"LdapCrlMap")
Section 15.13.2.1.1,
Mapper Plug-in Modules
"LdapCaCertMap").
367

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents