Setting Up Publishing Of Cep Certificates And Crls - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

When setting up multiple CEP services, you can use the
differentiate one CEP service from another. For example, if you're setting up
separate CEP services for router and VPN-client certificates and want to set
different extensions in these certificates, you can make that happen with the help of
predicates.
Setting Up Publishing of CEP Certificates and
CRLs
Set up the Directory for Publishing CEP Certificates and CRLs
You need to do the following to set up the directory to publish CEP Certificates and
CRLs:
Set up the schema in the directory for publishing. Chapter 15, "Publishing"
contains information on setting up Netscape Directory Server for publishing
certificates and CRLs—it covers directory schema required for publishing
certificates and the attributes to which a Certificate Manager publishes
end-entity certificates and CRLs.
Verify that the Directory Server schema can accommodate VPN clients. You
may need to update the Directory Server's schema. The reason for this is, if you
plan on publishing certificates from routers, they may need to be published
with the same DN as their certificate subject names. For example, if the
certificate subject name contains
components, you may need to add them to the directory schema.
unstructuredAddress, 1.2.840.113549.1.9.7, string
unstructuredName, 1.2.840.113549.1.9.8, string
Check the directory documentation for instructions on changing the schema.
The Directory Server port must be 389. To find out the port number assigned to
Directory Server, check it's configuration file (which is at
<server_root>/slapd-*/slapd.oc.conf
and change the port number from Netscape Console.
You will need publish certificates and CRLs to the same tree in the directory;
you may customize this if you desire. We recommend that you publish to a tree
named after the
O
will also need to have an
automatically.
UnstructuredAddress
attribute in your CA signing certificate. Router certificates
inserted in the subject name; this can be done
O
cepsubstore
or
UnstructuredName
). Alternatively, you can also find
Chapter 9
CEP Enrollment
attribute to
Authentication
419

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

Certificate management system 6.1

Table of Contents