Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 390

Table of Contents

Advertisement

Automated Enrollment
In the CMS window of the Certificate Manager or Registration Manager that
1.
processes certificate requests, select the Configuration tab.
Select Authentication in the navigation tree.
2.
The right pane shows the Authentication Instance tab listing currently
configured authentication instances.
Click Add.
3.
The Select Authentication Plug-in Implementation window appears.
Select
4.
select
Click Next.
5.
The Authentication Instance Editor window appears.
Fill in the following fields in the Authentication Instance Editor window:
6.
Authentication Instance ID. Accept the default instance name, or enter a new
name. If you choose to use a different name, be sure to edit this name in the
hidden value in the enrollment forms.
dnpattern. Specifies a string representing a subject name pattern to formulate
from the directory attributes and entry DN. See "DNs in Certificate
Management System" on page 750.
ldapStringAttributes. Specifies the list of LDAP string attributes that should
be considered authentic for the end entity. If specified, the values
corresponding to these attributes will be copied from the authentication
directory into the authentication token—that is, values retrieved from this
parameter can be used by policy modules to formulate subject names for
certificates or to make other policy decisions. For details, see
"SubjectAltNameExt" on page 557. Entering values for this parameter is
optional.
ldapByteAttributes. Specifies the list of LDAP byte (binary) attributes that
should be considered authentic for the end entity. If specified, the values
corresponding to these attributes will be copied from the authentication
directory into the authentication token for use by other modules—that is,
values retrieved from this parameter can be used by policy modules to make
certain policy decisions or to add additional information to users' certificates.
For example, assume you have defined an LDAP binary attribute for storing
users' pictures or fingerprints in your directory. You could develop a policy
plug-in that adds users' pictures to their certificates as extensions.
390
Netscape Certificate Management System Administrator's Guide • February 2003
for authentication based on user ID and password,
UidPwdDirAuth
for authentication based on DN and password.
UdnPwdDirAuth

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents