Step 2. Configure The Certificate Manager For Publishing Certificates And Crls - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

The Directory Server port—note the port number assigned to the configuration
directory; it must be 389. If you installed Certificate Management System with
the default choices, you may skip this step; the default port assigned to the
configuration directory is 389. To find out the port number assigned to
Directory Server, check it's configuration file (which is at
<server_root>/slapd-*/slapd.oc.conf
and change the port number from Netscape Console.
Step 2. Configure the Certificate Manager for
Publishing Certificates and CRLs
In this step, you configure the Certificate Manager to issue router and VPN-client
certificates with CRL Distribution Point Extension and to publish the certificates to a
directory.
Create an instance of the mapper plug-in named
publisher plug-in named
instances, you should create a publishing rule for publishing router certificates.
For instructions, see "Step B. Add Mappers, Publishers, and Publishing Rules"
on page 642.
Note that the publishing rule must be configured to use the mapper and
publisher you create for router certificates. In addition, the predicate
expression must be set to
Configure CRL publishing details; for instructions, see "Step 4. Configure the
Certificate Manager to Publish CRLs" on page 648.
Identify the directory for publishing. For instructions, see "Step 5. Identify the
Publishing Directory" on page 656.
Create an instance of the policy plug-in named
(following the instructions in "Step 4. Add New Policy Rules" on page 594) for
router certificates. This extension, if present in a certificate, enables the user of
the certificate to find revocation information pertaining to that certificate.
When you create an instance of the
sure to leave the
HTTP_PARAMS.certType==CEP-Request
LdapUserCertPublisher
HTTP_PARAMS.certType==CEP-Request
CRLDistributionPointsExt
and
issuerName
issuerType
Setting up CEP Enrollment Manually
). Alternatively, you can also find
LdapExactMapper
. Once you create these
CRLDistributionPointsExt
fields blank and to enter
in the
field.
predicate
Chapter 25
Setting Up CEP Enrollment
and of the
.
plugin, be
813

Advertisement

Table of Contents
loading

Table of Contents