Profile Policy Set
Defaults
Constraints
Type:RFC822Name,Enable:
true}
.
set9 - SigningAlg
Populates the certificate signing al-
gorithm. The default value is
Al-
gorithm=SHA1withRSA
.
Accepts only the following signing
algorithms:
SHA1withRSA
SHA256withRSA
SHA512withRSA
MD5withRSA
MD2withRSA
Table 2.2. caUserCert - Profile Policy Sets
•
Profile outputs.
The
Certificate
Output
output displays the certificate in pretty print format and cannot be configured or
changed. This output needs to be specified for any automated enrollment. Once a user successfully authenticates using
the automated enrollment method, the certificate is automatically generated, and this output page is returned to the
user. In an agent-approved enrollment, the user can get the certificate, once it is issued, by providing the request ID in
the CA end-entities page. (There is no output page associated with agent-approved enrollment.)
4. How Certificate Profiles Work
An administrator sets up a certificate profile by associating an existing authentication plug-in, or method, with the certific-
ate profile; enabling and configuring defaults and constraints; and defining inputs and outputs. The administrator can use
the existing certificate profiles, modify the existing certificate profiles, create new certificate profiles, and delete any certi-
ficate profile that will not be used in the PKI.
Once a certificate profile is set, it appears on the Manage Certificate Profiles page, where an agent can approve, and thus
enable, a certificate profile. Once the certificate profile is enabled, it appears on the Certificate Profile tab of the end-
entities page, so end entities can enroll for a certificate using the certificate profile.
The certificate profile enrollment page contains links to each type of certificate profile enrollment that has been enabled.
When an end entity selects one of those links, an enrollment page appears, containing the enrollment form specific to that
certificate profile. The enrollment page for the certificate profile in the end-entities page is dynamically generated from the
inputs defined for the certificate profile. If an authentication plug-in is configured, additional fields may be added that are
needed to authenticate the user with that authentication method.
A manual enrollment is a request when no authentication plug-in is configured. When the end entity submits a certificate
profile request with a manual enrollment, the certificate profile is queued in the agent services page as a certificate profile
enrollment request. The agent can change the request, reject it, change the status, or approve it. The agent can also update
the request without submitting it or validate that the request adheres to the profile's defaults and constraints. Agents are
bound by the constraints set in the profile; they cannot change the request so that a constraint is violated. The signed ap-
proval is immediately processed, and a certificate is issued.
When a certificate profile is associated with an authentication method, the request generates a certificate automatically if
the user successfully authenticates, all required information is provided, and the request does not violate any of the con-
straints set for the certificate profile.
The issued certificate contains the default content for the certificate profile (like the extensions and validity period) and
follows the constraints set for each default. There can be more than one policy set (pair of defaults and constraints); each
set is distinguished by using the same value for the policy set ID for the default and constraint in the set. The server evalu-
ates each policy set for each request it receives. When a single certificate is issued, one set is evaluated, and any other sets
are ignored. When dual key pairs are issued, the first policy set is evaluated with the first certificate request, and the
second set is evaluated with the second certificate request. There is no need for more than one policy set when issuing
single certificates or more than two sets when issuing dual key pairs.
4. How Certificate Profiles Work
Profiles
Summary of Contents for CERTIFICATE SYSTEM 7.2 - AGENT GUIDE
Page 1: ...Red Hat Certificate System Agent Guide 7 2 ...
Page 3: ......