Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 645

Table of Contents

Advertisement

Table 15-10 LdapDNCompsMap Configuration Parameters
Parameter
baseDN
dnComps
filterComps
Description
Specifies the DN to start searching for an entry in the publishing
directory. If you leave the dnComps field blank, the server uses the
base DN value to start its search in the directory.
Specifies where in the publishing directory the Certificate
Manager should start searching for an LDAP entry that matches
the CA's or the end entity's information.
The server uses the dnComps values to form an LDAP entry to
begin a subtree search. The server gathers values for these
attributes from the certificate subject name and uses the values to
form an LDAP DN, which then determines where in the LDAP
directory the server starts its search. For example, if you set
dnComps to use the O and C attributes of the DN, the server starts
the search from the O=<org>, C=<country> entry in the
directory, where <org> and <country> are replaced with values
from the DN in the certificate.
If you leave the dnComps field empty, the server checks the
baseDN field and searches the directory tree specified by that DN
for entries matching the filter specified by filterComps
parameter values.
Permissible values: Valid DN components or attributes separated
by commas.
Specifies components the Certificate Manager should use to filter
entries from the search result. The server uses the filterComps
values to form an LDAP search filter for the subtree. The server
constructs the filter by gathering values for these attributes from
the certificate subject name; it uses the filter to search for and
match entries in the LDAP directory.
If the server finds one or more entries in the LDAP directory that
match the information gathered from the certificate, the search is
successful and the server optionally performs a verification. For
example, if filterComps is set to use the email and user ID
attributes (filterComps=e, uid), the server searches the
directory for an entry whose values for email and user ID match
the information gathered from the certificate.
Permissible values: Valid directory attributes (in the certificate
DN) separated by commas. The attribute names for the filters need
to be attribute names from the certificate, not from ones in the
LDAP directory. For example, most certificates have an E attribute
for the user's email address; LDAP calls that attribute mail.
Mappers
Chapter 15
Publishing
645

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents