Selecting Dns For Certificates; Dn Patterns And Certificate Subject Names - Netscape MANAGEMENT SYSTEM 6.0 - PLUG-IN Manual

Table of Contents

Advertisement

DNs in Certificate Management System
For example:
CN=Example Corporation Certificate Authority, O=Example
Corporation, C=US

Selecting DNs for Certificates

Figure A-1 illustrates the structure of distinguished names you might select for CA
certificates, server certificates, and personal certificates.
Sample directory hierarchy
Figure A-1

DN Patterns and Certificate Subject Names

You can configure Certificate Management System to issue certificates with subject
names that are formulated from the directory attributes and entry DN. The
configuration variable of the automated-enrollment modules, such as
dnpattern
and
, described in Chapter 1, "Authentication
UidPwdDirAuth
UidPwdPinDirAuth
Plug-in Modules" enable you to configure the server to issue certificates with
required subject names. Note that
is a string representing a subject
dnpattern
name pattern to formulate from the directory attributes and entry DN. If empty or
not set, Certificate Management System uses the LDAP entry DN as the certificate
subject name.
The
configuration variable supports escaped commas and multiple
dnpattern
attribute variable assertions (AVAs) in a RDN. Below is the syntax for the DN
pattern followed by examples.
Appendix A
Distinguished Names
321

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents