Chapter 2. Making Rules for Issuing Certificates
Profile ID
caCACert
caCMCUserCert
caDirUserCert
caDirUserRenewal
42
Profile Name
Manual Certificate Manager
Signing Certificate Enrollment
Signed CMC-Authenticated
User Certificate Enrollment
Directory-Authenticated User
Dual-Use Certificate Enrollment
Directory-Authenticated User
Certificate Self-Renew profile
Description
Enrolls Certificate Authority
certificates.
Enrolls user certificates by
using the CMC certificate
request with CMC Signature
authentication.
Enrolls user certificates with
directory-based authentication.
Renews user certificates
through directory-based
authentication. The user
certificate is issued as soon
as the requester successfully
authenticates to the LDAP
directory.
NOTE
Renewal profiles
can only be used
in conjunction with
the profile that
issued the original
certificate. There
are two settings
that are beneficial:
• It is important
the the original
enrollment profile
name does not
change.
• The Renew
Grace Period
Constraint
should be set
in the original
enrollment
profile. This
defines the
amount of time
before and after
the certificate's
expiration date
when the user is
allowed to renew
the certificate.
There are only
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?