Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual page 236

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Chapter 8. Publishing Certificates and CRLs
• A new user which is granted write access. The entry can be identified by the Certificate
Manager's DN, such as cn=testCA, ou=Research Dept, o=Example Corporation,
st=California, c=US.
NOTE
Carefully consider what privileges are given to this user. This user can be
restricted in what it can write to the directory by creating ACLs for the account.
For instructions on giving write access to the Certificate Manager's entry, see the
Directory Server documentation.
4. Set the directory authentication method for how the Certificate Manager authenticates to Directory
Server. There are three options: basic authentication (simple username and password); SSL
without client authentication (simple username and password); and SSL with client authentication
(certificate-based).
See the Red Hat Directory Server documentation for instructions on setting up these methods of
communication with the server.
8.2.3.2. Configuring LDAP Publishers
The Certificate Manager creates, configures, and enables a set of publishers that are associated with
LDAP publishing. The default publishers (for CA certificates, user certificates, CRLs, and cross-pair
certificates) already conform to the X.500 standard attributes for storing certificates and CRLs and do
not need to be changed.
Publisher
LdapCaCertPublisher
LdapCrlPublisher
LdapDeltaCrlPublisher
LdapUserCertPublisher
LdapCrossCertPairPublisher
Table 8.1. LDAP Publishers
8.2.3.3. Creating Mappers
Mappers are only used with LDAP publishing. Mappers define a relationship between a certificate's
subject name and the DN of the directory entry to which the certificate is published. The Certificate
Manager needs to derive the DN of the entry from the certificate or the certificate request so it can
determine which entry to use. The mapper defines the relationship between the DN for the user entry
and the subject name of the certificate or other input information so that the exact DN of the entry can
be determined and found in the directory.
When it is configured, the Certificate Manager automatically creates a set of mappers defining the
most common relationships. The default mappers are listed in
Mapper
LdapUserCertMap
214
Description
Publishes CA certificates to the LDAP directory.
Publishes CRLs to the LDAP directory.
Publishes Delta CRLs to the LDAP directory.
Publishes all types of end-entity certificates to the LDAP directory.
Publishes cross-signed certificates to the LDAP directory.
Description
Locates the correct attribute of user entries in the directory in order to publish user certific
Table 8.2, "Default
Mappers".

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents