Directory Authentication Method; Updating Certificates And Crls In A Directory - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Updating Certificates and CRLs in a Directory

Use the DN of an existing entry that has write access. For example, you can use
the entry of the Directory Manager or choose an alternative.
Give write access to a user entry created for this purpose. The entry can be
identified by the Certificate Manager's DN. For example, it may look like this:
CN=testCA, OU=Research Dept, O=Example Corporation,
ST=California, C=US
Note, you need to carefully consider what privileges you give this user. You
may want to restrict exactly what this user can write to the directory by setting
ACLs that restrict this user's rights. For instructions on giving write access to
the Certificate Manager's entry, see your LDAP directory documentation.

Directory Authentication Method

Depending on how you want the Certificate Manager to authenticate to the
directory, you must set up Directory Server for one of the following methods of
communication:
Publishing With Basic Authentication
Publishing Over SSL Without Client Authentication
Publishing Over SSL With Client Authentication
See the Netscape Directory Server documentation for complete instructions on
setting up these methods of communication with the server.
Updating Certificates and CRLs in a Directory
The Certificate Manager and the publishing directory can become out of sync if
certificates are issued or revoked while Directory Server is down. Certificates that
were issued or revoked need to be published or unpublished manually when
Directory Server comes back up.
To help find certificates that are out of sync with the directory—that is, valid
certificates that are not in the directory and revoked or expired certificates that are
still in the directory—the Certificate Manager keeps a record of whether a
certificate in its internal database has been published to the directory. If the
Certificate Manager and the publishing directory become out of sync, you can use
the Update Directory option in the Certificate Manager Agent Services interface to
synchronize the publishing directory with the internal database.
658
Netscape Certificate Management System Administrator's Guide • June 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents