Step 9. Deliver Pins To End Users - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

If you've set up the directory- and PIN-based authentication with PIN
8.
removal, reenroll for another certificate using the same PIN. Your request
should get rejected.
If you've set up the portal enrollment, verify that an entry for the user is
9.
created in the directory. For example, you can point your browser to the portal
directory and find out if an entry for the user for whom you requested the
certificate exists.
In the URL field, type
ldap://<host_name>:<port>/<base_dn>??sub?(uid=<user_id>)
substituting
<host_name>
Server,
<port_number>
listening to authentication requests from the Certificate Manager
with the DN to start searching for the user's entry, and
of the user for whom you requested the certificate.
For example, if the directory host name is
base DN is
O=example.com
this:
ldap://corpDirectory:389/O=example.com??sub?(uid=jdoe)
In the resulting page, look for the user's credentials and verify that they match
what you specified in the enrollment form. If you've configured Certificate
Management System to publish certificates to the same directory (, "Setting Up
LDAP Publishing"), you will be able to see the certificate-related information;
it typically includes information such as the owner of the certificate, the CA
that has issued the certificate, the serial number, the validity period, and the
certificate fingerprint.

Step 9. Deliver PINs to End Users

This step is applicable for directory- and PIN-based authentication with or without
PIN removal.
After you have confirmed that the PIN-based enrollment works (as it should),
deliver the PINs to users so they can use them during enrollment. To protect the
privacy of PINs, be sure to use a secure, out-of-band method for delivery. Here are
a few suggested delivery methods:
Encrypted email (S/MIME)—if your company has S/MIME mail set up, you
can deliver PINs to users by encrypted mail.
Configuring Authentication for End-User Enrollment
with the fully qualified host name of the Directory
with the port number at which the Directory Server is
corpDirectory
, and user's ID is
jdoe
Chapter 15
,
<base_dn>
with the ID
<user_id>
, port number is
, the URL would look like
Setting Up End-User Authentication
,
389
523

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents