Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 397

Table of Contents

Advertisement

./setpin host=yourhost port=9446 length=11 input=infile
output=outfile write "binddn=cn=pinmanager,o=example.com"
bindpw="netscape" basedn=o=netscape.com "filter=(uid=u*)"
Use the output file for delivering PINs to users after you complete setting up
7.
the required authentication method.
After you have confirmed that the PIN-based enrollment works, deliver the PINs
to users so they can use them during enrollment. To protect the privacy of PINs, be
sure to use a secure, out-of-band method for delivery.
Policy Setup for Replicated Directories
If your directory is replicated, pins may not be removed from the replicas for some
period after they have been removed from the master. The removal of the pins
from the replica does not occur until it is updated by the master. During this time
period, a user could theoretically apply for another certificate if the replica is used
to authenticate the user.
To avoid this problem, you need to enable the
policy in the Certificate Manager that actually issues the certificates; see
"AttributePresentConstraints" on page 495. This policy forces the Certificate
Manager to check the master directory before issuing the certificate. If the
Registration Manager uses a Directory Server replica to authenticate users, and the
user successfully authenticates to a replica that still contains the pin, the Certificate
Manager will reject the request when this policy is enabled since the Certificate
Manager checks the master directory in which the pin has been removed.
Setting Up the UidPwdPinDirAuth Authentication
To setup this method of authentication:
In the CMS window of the Certificate Manager or Registration Manager that
1.
processes certificate requests, select the Configuration tab.
Select Authentication in the navigation tree.
2.
The right pane shows the Authentication Instance tab listing currently
configured authentication instances.
Click Add.
3.
The Select Authentication Plug-in Implementation window appears.
Select the
4.
UidPwdPinDirAuth
Click Next.
5.
The Authentication Instance Editor window appears.
AttributePresentConstraints
plug-in module.
Automated Enrollment
Chapter 9
Authentication
397

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents