Filtercomps; Verifycert - Netscape CONSOLE 6.0 - MANAGING SERVERS Manual

Managing servers with netscape console
Table of Contents

Advertisement

Using Client Authentication
For example, if you set
the search from the
country
If there isn't a
CmapLdapAttr
determine where to start searching.
If the
directory tree for entries matching the filter specified by
The following RDN keywords are supported for
and
mail
mail

FilterComps

FilterComps
gathering information from the user's DN in the client certificate. The server uses
the values for these keywords to form the search criteria for matching entries in the
LDAP directory. If the server finds one or more entries in the directory that match
the user's information gathered from the certificate, the search is successful and the
server performs a verification (if
For example, if
(
FilterComps=e,uid
for
e
Email addresses and user IDs are good filters because they are usually unique
entries in the directory.
The filter needs to be specific enough to match one and only one entry in the
directory. The following RDN keywords are supported for
,
,
c
l
can use

VerifyCert

VerifyCert
the certificate found in the user's directory entry. It takes one of two values:
. Setting the value to
off
unless the certificate presented exactly matches the certificate stored in the
directory. Setting the value to
200
Managing Servers with Netscape Console • December 2001
DNComps
o=org, c=country
are replaced with values from the DN in the certificate.
DNComps
setting or the entire subject DN in the client certificate to
entry is present but has no value, the server searches the entire
DNComps
. You can list the keywords in lower case or upper case. You can use
, but not both.
is a comma-separated list of RDN keywords used to create a filter by
FilterComps
), the server searches the directory for an entry whose values
and
match the user's information gathered from the client certificate.
uid
,
, and
. You can list the keywords in lower case or upper case. You
st
e
mail
or
, but not both.
e
mail
tells the server whether it should compare the client's certificate with
on
to use the
and
o
c
entry in the directory, where
entry in the mapping, the server uses either the
is set to
verifycert
is set to use the
and
e
ensures that the server will not authenticate the client
disables the verification process.
off
RDN keywords, the server starts
org
FilterComps
,
,
,
DNComps: cn
ou
o
c
).
on
attribute keywords
uid
FilterComps
and
.
,
,
,
,
l
st
e
or
e
:
,
,
,
cn
ou
o
or
on

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 6.0

Table of Contents