Introduction to Authentication
Chapter
15
Setting Up End-User Authentication
497
If you want to change the form content to suit your organization’s requirements,
edit the following file:
<server_root>/cert-<instance_id>/web-apps/ee/<subsystem>/UserRenewa
l.html
For details on individual form elements, see the online help available by clicking
the Help button on the form. For more information on customizing the form, see
CMS Customization Guide. To locate an online version of this guide, open the
<server_root>/manual/index.html
file.
Authentication of End Users During Certificate Revocation
Certificates can be revoked by administrators, agents, and end users. When an end
user submits a certificate revocation request, the first step in the revocation process
is for the Certificate Manager or Registration Manager to identify and authenticate
the end user. The reason for this is when an end user attempts to revoke a
certificate, the server needs to verify that the user is attempting to revoke his or her
own certificate, not a certificate belonging to someone else.
Both Certificate Manager and Registration Manager support the following
methods of revocation:
•
SSL client authenticated revocation
This method requires an end user to present a valid or revoked certificate that
has the same subject name as the one he or she wants to revoke. Without the
certificate, the user won’t be able to revoke the certificate.
•
Challenge-password-based revocation
This method requires an end user to enroll for a personal certificate using the
manual enrollment method. The reason for this is, by default, only the manual
enrollment form includes fields for entering the challenge password when
requesting a certificate. None of the other enrollment forms, for example
directory-based or NIS server-based forms, by default allow end users to
specify a challenge password.
You can use the manual-enrollment form (
ManUserEnroll.html
) as a model
and introduce the input fields for entering the challenge password in any of the
other end user enrollment forms. Keep in mind that this feature is available for
end-user certificates only; the feature is not available for other types of
certificates.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...