Publishing of Certificates to a Directory
Chapter
19
Setting Up LDAP Publishing
589
The Certificate Manager cannot update the directory in the following cases:
•
If an end-entity entry is not present or if an entry cannot be found to publish
the certificate.
•
If the directory’s schema doesn’t include the appropriate attributes. To
configure the directory for LDAP publishing, see “Step 2. Set Up the Directory
for Publishing” on page 598. Note that the Certificate Manager publishes to the
userCertificate;binary
attribute, which is an LDAP v3 standard. Unless
you are using a non-standards compliant directory, this situation shouldn’t
arise.
•
When the directory is unreachable because maintenance work is being
performed, or because of network or system failures.
Note that the Certificate Manager’s LDAP publishing action happens as a separate
transaction from any certificate operation (such as issuance); the operation of a
certificate is not affected by whether it was successfully published or not.
Directory Update Process
As indicated in Table 19-1 on page 588, when a Certificate Manager is requested to
issue a certificate, update certificate information, or publish a CRL, it automatically
updates the corresponding entry in the configured directory with relevant
information. To locate the correct directory entry, the Certificate Manager relies on
object-mapping rules, which can be defined using the mapper modules. Once an
entry is located in the directory, to publish the object to the correct attribute of the
located entry, the Certificate Manager relies on object-publishing rules, which can
be defined with the help of publisher modules. For details about mapper and
publisher modules, see Chapter 5, “Mapper Plug-in Modules” and Chapter 6,
“Publisher Plug-in Modules” of CMS Plug-Ins Guide.
Similarly, when you revoke a certificate, the Certificate Manager uses the object
mapping and publishing rules to locate and delete the corresponding certificate
from the directory.
For step-by-step instructions to configure a Certificate Manager to publish to an
LDAP directory, see “Configuring a Certificate Manager to Publish Certificates and
CRLs” on page 595.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...