Steps in End-Entity Enrollment
82
Netscape Certificate Management System Installation and Setup Guide • May 2002
2.
Authenticate user.
Authentication can be either automatic or manual. If the
CMS manager is configured for automatic authentication, the servlet uses the
authentication module specified by the form to validate the information
provided by the user. For example, the directory authentication module that
comes with Certificate Management System validates the user ID and
password by comparing it to the user’s entry in an LDAP directory. Custom
authentication modules can be used to take advantage of existing databases,
security systems, or other methods of authentication. If the CMS manager is
configured for manual authentication, the servlet routes the request to the
request queue and informs the user (via a web page) that approval has been
deferred. The request remains in the queue until an agent approves it or rejects
it.
3.
Process policies.
If authentication is successful, policies specified for this CMS
manager are applied to the request for the purpose of formulating the contents
of the certificate to be issued and to enforce certain rules, such as name
constraints. Custom policy modules can be used to enforce specialized
certificate extensions and other requirements.
4.
Service request.
After policy processing, the servlet’s work is finished and the
CMS manager services the request (assuming that a policy has not triggered
deferral)—for example, by issuing a certificate.
5.
Notify user.
If the CMS manager has been configured for automatic
authentication and issuance, the manager delivers the signed certificate to the
user via a web page. If the request has been deferred (for example, for manual
approval) or rejected, the user is informed of the request’s status. When the
request has been approved and the certificate issued, the CMS manager
notifies the user (for example, with an email) and provides a URL where the
certificate can be picked up.
Since all three CMS managers use the same architecture for authentication and
policy processing, it’s possible to reuse any authentication and policy modules
with any manager. For information on the relationship of policy modules to the
APIs exposed by Certificate Management System, see “System Architecture” on
page 74.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...