Enrollment Forms - Netscape MANAGEMENT SYSTEM 6.01 - PLUG-IN Manual

Table of Contents

Advertisement

General guidelines to set up certificate-based enrollment (for dual certificates) are
as follows:
On the server side you need do the following:
On the client side, you need to do the following:

Enrollment Forms

The end-entity interface of the Certificate Manager and the Registration Manager
include default HTML forms for all the authentication methods—manual and
automated—supported by the server.
Enrollment forms can be categorized into two types, depending on the
authentication method they support.
Manual enrollment forms—these forms work with the built-in manual
authentication module (see "Manual Authentication" on page 21), enabling
users to request all types of certificates such as client certificates, server
certificates, object-signing certificates, CA certificates, and so on. Manual
Customize the enrollment form you want your users to use for enrollment.
Enable the appropriate enrollment option, such as directory-based
enrollment or NIS-server based enrollment. Be sure to configure the
authentication module to compose the desired DN pattern.
Enable the Key Usage extension policy explained in "KeyUsageExt Plug-in
Module" on page 186.
Take a look at the key-usage policy rule named
and see if it needs any modifications. For example, to get a signing-only
certificate, you need to turn off
bits of the extension; similarly, to get an encryption-only certificate, you
may need to turn off the
Configure the
IssuerRule
predicate expression so that the rule is applied to client certificates only.
Install drivers for the hardware tokens you want to use during bulk
generation of key pairs and corresponding certificates with generic subject
names.
If you want to issue dual certificates, install a client that can generate dual
key pairs; for example, Netscape Communicator (version 4.7 or later) with
Netscape Personal Security Manager.
keyEncipherment
bit of the extension.
digitalSignature
policy with the correct issuer DN and set the
Chapter 1
Enrollment Forms
ClientCertKeyUsageExt
and
dataEncipherment
Authentication Plug-in Modules
53

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents