Dns In Certificate Management System - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

DNs in Certificate Management System

Typically, an LDAP search consists of the following components:
The base DN—for example,
search through all entries below this entry in the directory (in other words, all
entries with the suffix
The search type, which can be a base search (only the entry specified by the
base DN is searched), a one-level search (only entries one level below the base
entry are searched), or a subtree search (all entries at all levels below the base
entry are searched).
The search filter, which specifies the search criteria applied to each entry
within the scope of the search.
When Certificate Management System is configured for LDAP publishing, the
search point and search criteria are determined by the configuration parameter
values. In the absence of a base DN value, Certificate Management System uses DN
components in the certificate's subject name to construct the base DN so that it can
search the directory in order to publish to or update the appropriate directory
entry.
Typically, when you configure Certificate Management System for LDAP
publishing, you set the base DN value to
publishing directory's root entry to start searching; see section "Configuring a
Certificate Manager to Publish Certificates and CRLs" in Chapter 19, "Setting Up
LDAP Publishing" of CMS Administrator's Guide.
DNs in Certificate Management System
In Certificate Management System, the characters allowed in a DN are based on the
components (attributes) as defined in the X.509 standard.
Table I-2 lists the attributes supported by default and their character sets.
Explanation of the character sets are in Table I-3. The set of attributes is extensible.
Allowed characters for value types
Table I-2
Attribute
CN
OU
O
750
Netscape Certificate Management System Administrator's Guide • February 2003
O=example.com
,
O=example.com
Directory Manager
Value type
Directory String
Directory String
Directory String
,
, which initiates a subtree
C=US
).
C=US
, so that it can use the
Object identifier
2.5.4.3
2.5.4.11
2.5.4.10

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents