Agent-Approved Enrollment; Setting Up Agent-Approved Enrollment - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

To create dual-key pairs, and the resultant certificates associated with each key,
you need to enable this function by changing the javascript found in the enrollment
page. You use any method of authentication, chaining it to enable dual-key pairs
by modifying the javascript on that enrollment page. There are instructions,
presented as HTML comments, in the forms describing how to change the
javascript. Basically, you need to add some lines to the javascript and you are ready
to go.
When you set up dual-key pairs, you should check your policy or certificate profile
set up and set your policies or certificate profiles to work correctly when
generating separate certificates for signing and encryption.

Agent-Approved Enrollment

Both the Registration Manager and Certificate Manager are initially configured for
agent-approved enrollment. An end entity makes a request which is then sent to
the agent services interface for an agent's approval. An agent can change some
aspects of the request, change the status of the request, reject the request, or
approve the request. Once the request is approved, the signed request is sent to the
Certificate Manager for processing. The Certificate Manager processes the request
and issues the certificate.
The agent-approved enrollment method is not configurable. If you don't configure
a Certificate Manager or Registration Manager for any other enrollment method,
the server automatically sends all certificate-related requests to a queue where they
await agent approval. This ensures that all requests that lack authentication
credentials are sent to the request queue for agent approval.

Setting Up Agent-Approved Enrollment

To set up agent-approved enrollment you do the following:
Set any policies for certificate extensions, or for constraints on certificates, see
Chapter 11, "Policies" for information about policies. Alternatively, you can
enroll users through the certificate profile functionality specifying
agent-approved enrollment and setting policies for specific certificates in the
certificate profile, see Chapter 10, "Certificate Profiles" for information about
policies.
Agent-Approved Enrollment
Chapter 9
Authentication
387

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents