Chapter 9. Authentication for Enrolling Certificates
244
If the authentication entries are not separated by an empty line, then when the router attempts to
authenticate to the CA, it will fail. For example:
...
flatfile.txt entry
...
UID:192.168.123.123
PIN:HU89dj
UID:12.255.80.13
PIN:fiowIO89
...
error log entry
...
[13/Jun/2009:13:03:09][http-9180-Processor24]: FlatFileAuth: authenticating user: finding user
from key: 192.168.123.123
[13/Jun/2009:13:03:09][http-9180-Processor24]: FlatFileAuth: User not found in password file.
9.3. Setting up CMC Enrollment
CMC enrollment sets up an enrollment client, signs the certificate request with an agent certificate,
and then sends the signed request to the Certificate Manager. When this method is set up, the
Certificate Manager automatically issues certificates when a valid request signed with the agent
certificate is received.
The CMCAuth authentication plug-in also activates CMC revocation. CMC revocation sets up a
revocation client, signs the request with the agent certificate, and then sends the signed request to
the Certificate Manager. When this method is set up, the Certificate Manager automatically revokes
certificates when a valid request signed with the agent certificate is received.
To set up CMC enrollment:
1. Set up the certificate profile to use to enroll users by setting policies for specific certificates in the
certificate profile. See
Chapter 2, Making Rules for Issuing Certificates
for information about profile
policies.
2. If necessary, set up the CMCAuth authentication plug-in. An instance of this plug-in module is
created and enabled by default. It has no configuration parameters. When the instance is enabled,
CMC enrollment and CMC revocation are both enabled for the server.
a. Open the CA Console.
pkiconsole https://server.example.com:9445/ca
b. In the
Configuration
tab, select
Authentication
in the navigation tree.
The right pane shows the
Authentication Instance
tab listing currently configured
authentication instances.
c. Click
Add
.
The
Select Authentication Plug-in Implementation
window appears.
d. Select the CMCAuth plug-in module.
e. In the
Authentication Instance ID
field, type a unique name for this instance that will identify
it if the default name is not to be used.
There are no configuration options for this plug-in; it simply enables this functionality.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...