Netscape ENTREPRISE SERVER 6.1 - 04-2002 ADMINISTRATOR Administrator's Manual page 129

Table of Contents

Advertisement

certmap usps ou=United States Postal Service, o=usps, c=US
usps:DNComps ou,o,c
usps:FilterComps e
usps:verifycert on
When the server gets a certificate from anyone other than the US Postal Service, it
uses the default mapping, which starts at the top of the LDAP tree and searches for
an entry matching the client's email and userid. If the certificate is from the US
Postal Service, the server starts its search at the LDAP branch containing the
organizational unit and searches for matching email addresses. Also note that if the
certificate is from the USPS, the server verifies the certificate; other certificates are
not verified.
The issuer DN (that is, the CA's information) in the certificate must
CAUTION
be identical to the issuer DN listed in the first line of the mapping. In
the previous example, a certificate from an issuer DN that is
o=United States Postal Service,c=US
there isn't a space between the
Example #3
The following example uses the
database for an attribute called
entire subject DN taken from the client certificate.
certmap myco ou=Example Corporation, o=example, c=US
example:CmapLdapAttr certSubjectDN
example:DNComps
example:FilterComps mail, uid
example:verifycert on
If the client certificate subject is:
uid=Babs Jensen, o=Example Corporation, c=US
the server first searches for entries that contain the following information:
certSubjectDN=uid=Babs Jensen, o=Example Corporation, c=US
If one or more matching entries are found, the server proceeds to verify the entries.
If no matching entries are found, the server will use
search for matching entries. In this example, the server would search for
in all entries under
Jensen
NOTE
This example assumes the LDAP directory contains entries with the
attribute
CmapLdapAttr
certSubjectDN
o, c
o=Example Corporation, c=US
.
certSubjectDN
Setting Client Security Requirements
won't match because
and the
attributes.
o
c
property to search the LDAP
whose value exactly matches the
and
DNComps
.
Chapter 5
Securing Your Enterprise Server
to
FilterComps
uid=Babs
129

Advertisement

Table of Contents
loading

This manual is also suitable for:

Entreprise server 6.1

Table of Contents