Setting up the Server for Multiple Requests in a Full CMC Request
245
f.
Click
OK
. The authentication instance is now set up and enabled.
3. Use the
CMCEnroll
utility to sign certificate requests with the agent certificate.
This utility has the following syntax:
CMCEnroll -d
/certificate/directory
-h
password
-n
cert_nickname
-r
certrequest.file
-p
certDB_passwd
[-c]
Parameter
Description
d
The location of the directory containing the
cert8.db
,
key3.db
, and
secmod.db
files associated with the
agent certificate.
h
Password to the database specified in the
d
option.
n
The common name of the certificate.
r
The filename of the certificate request.
p
The password to the browser certificate database.
c
Optional.
Includes a comment about the request.
Table 9.1. CMCEnroll Usage Options
NOTE
Surround values that include spaces in quotation marks.
9.3.1. Setting up the Server for Multiple Requests in a Full CMC
Request
CMC supports multiple CRMF or PKCS #10 requests in a single full CMC request. If the
numRequests
parameter in the
.cfg
file is larger than 1, modify the server's certificate profile by
doing the following:
1. By default, the servlet processing a full CMC request uses the
caFullCMCUserCert
profile. This
profile only handles a single request.
2. To use the new profile instead of the default, modify the
web.xml
file in the
/var/lib/pki-
ca/webapps/WEB-INF/
directory. Locate the servlet which processes the full CMC request; by
default, this is
/ca/profileSubmitCMCFull
. Change the value for the
profileID
parameter
to the name of the new profiles.
NOTE
To modify the profile for the end-user services, edit the profiles in the
/var/lib/
pki-ca/webapps
directory. If the services are not separated, edit the profiles in the
/var/lib/pki-ca/webapps
(agent services) directory.
For information on creating a new profile, see
Chapter 2, Making Rules for Issuing Certificates
.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...