Issuing Cross-Pair Certificates; Importing Cross-Pair Certificates; Publishing Cross-Pair Certificates - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Federal Bridge CA

Issuing Cross-Pair Certificates

The policy feature allows you to configure the policy
and provide
up any other necessary policies for this kind of certificate. You would then
associate an end-entity enrollment page, customized to enroll for cross-pair
certificates, providing the hidden value
associated with FBCA to this request.
You can also use the Certificate Setup wizard to create a cross-pair certificate
request that can be sent to another CA. You might create this request and then
paste it into an existing end-entity interface enrollment page, or a customized page
that requires a request rather than forming the request from that page.
See Chapter 11, "Policies" for more information about policies.

Importing Cross-Pair Certificates

CMS provides the capability to import the cross-pair certificates from each of the
CAs. You use the Certificate Setup wizard to import both certificates. When both
certificates have been imported into the database, a
formed and stored in the database. The original certificates are deleted once the
crossCertificatePair
You can search for and view a
following LDAP search command:
./ldapsearch -h <yourHostName> -p <yourCAInternalDBPort >
-b "o=netscapeCertificateServer" -D "cn=Directory Manager"
-w <DirectoryManagerPassword> "cn=crossCerts"
See "Certificate Setup Wizard," on page 298" for more information about the
Certificate Setup Wizard.

Publishing Cross-Pair Certificates

You can publish cross-pair certificates (as a
LDAP directory or to a file. When you set up publishing, you can specify cross-pair
certificates in the rule you set up for this type of certificate by selecting
the type field of the Rule Editor window. CMS provides a rule called
LDAPXCertRule
128
Netscape Certificate Management System Administrator's Guide • February 2003
HTTP_PARAMS.certType==fbca
is formed.
crossCertificatePair
that is pre configured for publishing cross-pair certificates.
CertificatePoliciesExt
as the predicate value, and then set
, thus activating policies
certType==fbca
crossCertificatePair is
in the database using the
crossCertificatePair
) to either an
in
xcerts

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents