Dns In End-Entity Certificates; Dns In Ca Certificates - Netscape MANAGEMENT SYSTEM 6.01 - PLUG-IN Manual

Table of Contents

Advertisement

DNs in Certificate Management System

DNs in End-Entity Certificates

In end-entity certificates issued by Certificate Management System, DNs are used
to identify the end entity that owns the certified key pair. The end entity is one of
the following:
The individual who owns the certified key pair (for personal or client
certificates—to form this type of DN, use the
user's full name:
CN=<user's_full_name>, OU=<user's_division_name>,
O=<company_name>, C=<country_name>
For example:
CN=Jane Doe, OU=Human Resources, O=Example Corporation, C=US
The server that owns the certified key pair (for SSL server certificates)—to form
this type of DN, use the
host name in the form
CN=<host_name>, OU=<division_name>, O=<company_name>,
C=<country_name>
For example:
CN=corpDirectory.example.com, OU=Human Resources, O=Example
Corporation, C=US
When clients such as Netscape Navigator receive a server certificate, they
expect the
the URL. If the name in the certificate and the host name of the server do not
match, Navigator notifies the user and gives the user the choice of not
connecting to the server.
For example, if Navigator goes to the URL
https://corpDirectory.example.com
server, it expects the
corpDirectory.example.com
example,
certificate's subject name does not match the host name in the URL.

DNs in CA Certificates

In CA certificates issued by Certificate Management System (for both root and
subordinate CAs), DNs are used to identify the authority who owns the certified
key pair.
To form this type of distinguished name, use the
of your CA:
320
Netscape Certificate Management System Plug-Ins Guide • May 2002
component to specify the server's fully qualified
CN
<machine_name>.<your_domain>.<domain>
component of the certificate's subject to match the host name in
CN
component of the certificate's subject to be
CN
corpDir.example.com
CN=<CA_name>, O=<company_name>, C=<country_name>
component to specify the
CN
and receives a certificate from the
. If the
component has a different value (for
CN
), Navigator notifies the user that the
component to specify the name
CN
:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents