output.o1.class_id=certOutputImpl
Example 4.3. Agent-Based Renewal Profile
For directory-based authentication, the requester must log into an LDAP directory and authenticate
against that database, so the auth.instance_id parameter must be set to use directory
authentication.
desc=This certificate profile is for renewing a certificate by serial number by using
directory based authentication.
visible=true
enable=true
enableBy=admin
renewal=true
auth.instance_id=UserDirEnrollment
authz.acl=user_origreq="auth_token.uid"
name=Directory-Authenticated User Certificate Self-Renew profile
input.list=i1
input.i1.class_id=serialNumRenewInputImpl
output.list=o1
output.o1.class_id=certOutputImpl
Example 4.4. Directory-Based Renewal Profile
NOTE
Directory-based renewal works even if the UidPwdDir plug-in has optional fields
set to configure things such as the connection or the DN pattern. This is described in
Section 9.2.1, "Setting up Directory-Based
However, for certificate-based renewal, the certificate is presented directly by the browser being
used to open the renewal forms, and that certificate is checked in the client database. The certificate
is used both to verify the identity of the requester and to get the certificate information for renewal.
For certificate-based renewal, it is not necessary to specify a serial number input; instead, set the
authentication module to use certificate-based authentication.
auth.instance_id=SSLclientCertAuth
desc=This certificate profile is for renewing SSL client certificates.
visible=true
enable=true
enableBy=admin
renewal=true
auth.instance_id=SSLclientCertAuth
name=Self-renew user SSL client certificates
output.list=o1
output.o1.class_id=certOutputImpl
Example 4.5. Certificate-Based Renewal Profile
4.7.3. Renewing Certificates
Almost any certificate issued by Certificate System can be renewed (assuming the original issuing
profile allows it). Renewing certificates rather then requesting new certificates can be one way of
Authentication".
Renewing Certificates
121
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?
Questions and answers