The right pane shows the Authentication Instance tab, which lists the currently configured
authentication instances.
NOTE
The UidPwdDirAuth plug-in is enabled by default.
c. Click Add.
The Select Authentication Plug-in Implementation window appears.
d. Select UidPwdDirAuth for user ID and password authentication, or select UdnPwdDirAuth
for DN and password authentication.
e. Fill in the following fields in the Authentication Instance Editor window:
• Authentication Instance ID. Accept the default instance name, or enter a new name.
• dnpattern. Specifies a string representing a subject name pattern to formulate from the
directory attributes and entry DN.
• ldapStringAttributes. Specifies the list of LDAP string attributes that should be considered
authentic for the end entity. If specified, the values corresponding to these attributes are
copied from the authentication directory into the authentication token and used by the
certificate profile to generate the subject name. Entering values for this parameter is
optional.
• ldapByteAttributes. Specifies the list of LDAP byte (binary) attributes that should be
considered authentic for the end entity. If specified, the values corresponding to these
attributes will be copied from the authentication directory into the authentication token for
use by other modules, such as adding additional information to users' certificates.
Entering values for this parameter is optional.
• ldap.ldapconn.host. Specifies the fully-qualified DNS hostname of the authentication
directory.
• ldap.ldapconn.port. Specifies the TCP/IP port on which the authentication directory listens
to requests; if the ldap.ldapconn.secureConn. checkbox is selected, this should be the
SSL port number.
• ldap.ldapconn.secureConn. Specifies the type, SSL or non-SSL, of the port on which the
authentication directory listens to requests from the Certificate System. Select if this is an
SSL port.
• ldap.ldapconn.version. Specifies the LDAP protocol version, either 2 or 3. The default is
3, since all Directory Servers later than version 3.x are LDAPv3.
• ldap.basedn. Specifies the base DN for searching the authentication directory. The server
uses the value of the uid field from the HTTP input (what a user enters in the enrollment
form) and the base DN to construct an LDAP search filter.
Setting up Directory-Based Authentication
237
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?