Mappers
620
Red Hat Certificate System Administrator’s Guide • September 2005
Configuration Parameters of LdapDNCompsMap
With this configuration, a Certificate Manager maps its certificates with the ones in the
LDAP directory by using the
dnComps
values to form a DN and the
filterComps
values
to form a search filter for the subtree.
•
If the formed DN is null, the server uses the
baseDN
value for the subtree. If both the
formed DN and base DN are null, the server logs an error.
•
If the filter is null, the server uses the
baseDN
value for the search. If both the filter and
base DN are null, the server logs an error.
Table 16-10 describes these parameters.
NOTE
Generally, the
E
,
L
, and
ST
components are not included in the standard set
of certificate request forms provided for end entities. You can add these
components to the forms, or you can have the issuing agents insert these
components when editing the subject name in the certificate issuance
forms.
Table 16-10
LdapDNCompsMap Configuration Parameters
Parameter
Description
baseDN
Specifies the DN to start searching for an entry in the publishing
directory. If you leave the
dnComps
field blank, the server uses the base
DN value to start its search in the directory.
dnComps
Specifies where in the publishing directory the Certificate Manager
should start searching for an LDAP entry that matches the CA’s or the
end entity’s information.
The server uses the
dnComps
values to form an LDAP entry to begin a
subtree search. The server gathers values for these attributes from the
certificate subject name and uses the values to form an LDAP DN, which
then determines where in the LDAP directory the server starts its search.
For example, if you set
dnComps
to use the
O
and
C
attributes of the DN,
the server starts the search from the
O=
<
org
>,
C=
<
country
> entry in
the directory, where <
org
> and <
country
> are replaced with values
from the DN in the certificate.
If you leave the
dnComps
field empty, the server checks the
baseDN
field and searches the directory tree specified by that DN for entries
matching the filter specified by
filterComps
parameter values.
Permissible values: Valid DN components or attributes separated by
commas.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...