Setting Up Directory-Based Authentication - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

• AgentCertAuth. Agents who are successfully issued server certificates through an automated
process are automatically authenticated when they present the agent certificate. If the certificate
presented is the agent certificate stored in the database for the user ID, the request for the server
certificate is automatically processed. This plug-in is enabled by default and has no parameters.
This form of automatic authentication can be associated with the certificate profile for enrolling for
server certificates.

16.3.1. Setting up Directory-Based Authentication

The UidPwdDirAuth and the UdnPwdDirAuth plug-in modules implement directory-based
authentication. End users enroll for a certificate by providing their user IDs or DN and password to
authenticate to an LDAP directory.
Set up directory-based authentication by doing the following:
1. Create an instance of either the UidPwdDirAuth or UdnPwdDirAuth authentication plug-in
module and configure the instance.
a. Open the CA Console.
pkiconsole https://server.example.com:9443/ca
b. In the Configuration tab, select Authentication in the navigation tree.
The right pane shows the Authentication Instance tab, which lists the currently configured
authentication instances.
NOTE
The UidPwdDirAuth plug-in is enabled by default.
c. Click Add.
The Select Authentication Plug-in Implementation window appears.
d. Select UidPwdDirAuth for user ID and password authentication, or select UdnPwdDirAuth
for DN and password authentication.
e. Fill in the following fields in the Authentication Instance Editor window:
• Authentication Instance ID. Accept the default instance name, or enter a new name.
• dnpattern. Specifies a string representing a subject name pattern to formulate from the
directory attributes and entry DN.
• ldapStringAttributes. Specifies the list of LDAP string attributes that should be considered
authentic for the end entity. If specified, the values corresponding to these attributes are
copied from the authentication directory into the authentication token and used by the
certificate profile to generate the subject name. Entering values for this parameter is
optional.
Setting up Directory-Based Authentication
379

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents