Configuring Authentication for End-User Enrollment
Step B. Update the Directory
By default, the PIN Generator modifies the
Because this attribute is not part of the standard
that the user entries in your directory do not contain the
before you run the PIN Generator, you'll need to add the
entries in your directory—that is, you'll need to create a new object class (named
pinPerson
In general, you'll need to update the
attribute and the
The modified schema should look similar to this:
attribute pin bin
objectclass pinPerson
superior organizationalPerson
allows
In addition, if you want to make use of the PIN-removal feature—that is, remove a
user's PIN from the directory after Certificate Management System successfully
authenticates that user and thus prevents the user from enrolling for another
certificate—ACIs must be set up on the directory to prevent end users from
creating new PINs for themselves. To do this, you'll need to create an entry for a
PIN manager user with read-write permission to the
For your convenience, the PIN Generator tool comes with a configuration file,
named
authentication directory with changes required for setting up PIN-based
authentication. The configuration file is located in this directory:
<server_root>/bin/cert/tools
To make the required schema changes and add an entry for the PIN manager user
(using the configuration file):
Go to this directory:
1.
Open the
2.
Follow the instructions outlined in the file and make the appropriate changes.
3.
Typically, you will need to update the Directory Server's host name, Directory
Manager's bind password, and PIN manager's password.
Run the
4.
setpin.conf
504
Netscape Certificate Management System Installation and Setup Guide • March 2002
) in your authentication directory's schema.
slapd.user_oc.conf
pin
, which enables you to automate the process of updating the
setpin.conf
<server_root>/bin/cert/tools
file in a text editor.
setpin.conf
command with its
setpin
file (
setpin optfile=setpin.conf
attribute in a directory's user entry.
pin
organizationalPerson
pin
pin
slapd.user_at.conf
file to include the object-class definition.
attribute.
pin
option pointing to the
optfile
).
, it's likely
attribute. This means,
attribute to the user
file to include the
pin
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.0 and is the answer not in the manual?
Questions and answers