Chapter 9. Authentication for Enrolling Certificates
240
e. Fill in the following fields in the
Authentication Instance Editor
window:
•
Authentication Instance ID.
Accept the default instance name or enter a new name.
•
removePin.
Sets whether to remove PINs from the authentication directory after end users
successfully authenticate. Removing PINs from the directory restricts users from enrolling
more than once, and thus prevents them from getting more than one certificate.
•
pinAttr.
Specifies the authentication directory attribute for PINs. The
PIN Generator
utility sets the attribute to the value of the
objectclass
parameter in the
setpin.conf
file; the default value for this parameter is
pin
.
•
dnpattern.
Specifies a string representing a subject name pattern to formulate from the
directory attributes and entry DN.
•
ldapStringAttributes.
Specifies the list of LDAP string attributes that should be considered
authentic
for the end entity. Entering values for this parameter is optional.
•
ldapByteAttributes.
Specifies the list of LDAP byte (binary) attributes that should be
considered
authentic
for the end entity. If specified, the values corresponding to these
attributes will be copied from the authentication directory into the authentication token for
use by other modules, such as adding additional information to users' certificates.
Entering values for this parameter is optional.
•
ldap.ldapconn.host.
Specifies the fully-qualified DNS host name of the authentication
directory.
•
ldap.ldapconn.port.
Specifies the TCP/IP port on which the authentication directory listens
to requests from the Certificate System.
•
ldap.ldapconn.secureConn.
Specifies the type, SSL or non-SSL, of the port on which the
authentication directory listens to requests. Select if this is an SSL port.
•
ldap.ldapconn.version.
Specifies the LDAP protocol version, either
2
or
3
. By default, this
is
3
, since all Directory Server versions later than 3.x are LDAPv3.
•
ldap.ldapAuthentication.bindDN.
Specifies the user entry as whom to bind when
removing PINs from the authentication directory. Specify this parameter only if the
removePin
checkbox is selected. It is recommended that a separate user entry that has
permission to modify only the PIN attribute in the directory be created and used. For
example, do not use the Directory Manager's entry because it has privileges to modify the
entire directory content.
•
password.
Gives the password associated with the DN specified by the
ldap.ldapauthbindDN
parameter. When saving changes, the server stores the
password in the single sign-on password cache and uses it for subsequent start ups. This
parameter needs set only if the
removePin
checkbox is selected.
•
ldap.ldapAuthentication.clientCertNickname.
Specifies the nickname of the certificate to
use for SSL client authentication to the authentication directory to remove PINs. Make sure
that the certificate is valid and has been signed by a CA that is trusted in the authentication
directory's certificate database and that the authentication directory's
certmap.conf
file
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...