Managing Subject Names And Subject Alternative Names; Inserting Ldap Directory Attribute Values And Other Information Into The Subject Alt Name - Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Serial number management can be enabled for CAs which are not cloned, if the
parameters are set in the CS.cfg file.
dbs.beginSerialNumber=1
dbs.enableSerialManagement=true
dbs.endReplicaNumber=100
dbs.endRequestNumber=10000000
dbs.endSerialNumber=10000000
However, by default, serial number management is disabled unless a system is
cloned, when it is automatically enabled.
The serial number range cannot be updated manually through the console. The serial number
ranges are read-only fields. If cloning or serial number management is not enabled, then the
serial number range can be updated by editing the values in the CS.cfg file.
• Default Signing Algorithm. Specifies the signing algorithm the Certificate Manager
uses to sign certificates. The options are MD2withRSA, MD5withRSA, SHA1withRSA,
SHA256withRSA, and SHA512withRSA, if the CA's signing key type is RSA.
The signing algorithm specified in the certificate profile configuration overrides the algorithm set
here.
4. Click Save.
2.7. Managing Subject Names and Subject Alternative
Names
The subject name of a certificate is a distinguished name (DN) that contains identifying information
about the entity to which the certificate is issued. This subject name is built from standard LDAP
directory components, such as email addresses, common names, and organizational units. These
components are defined in X.500. In addition to — or even in place of — the subject name, the
certificate can have a subject alternative name, which is a kind of extension set for the certificate that
includes additional information that is not defined in X.500.
The naming components for both subject names and subject alternative names can be customized.
IMPORTANT
If the subject name is empty, then the Subject Alternative Name extension must be
present and marked critical.
2.7.1. Inserting LDAP Directory Attribute Values and Other
Information into the Subject Alt Name
Information from an LDAP directory or that was submitted by the requester can be inserted into
the subject alternative name of the certificate by using matching variables in the Subject Alt Name
Extension Default configuration. This default sets the type (format) of information and then the
matching pattern (variable) to use to retrieve the information. For example:

Managing Subject Names and Subject Alternative Names

61

Advertisement

Table of Contents
loading

Table of Contents