Chapter 9. Authentication for Enrolling Certificates
246
3. Restart the server.
service pki-ca restart
9.3.2. Testing CMCEnroll
1. Enable CMCEnroll.
2. Create a certificate request using the
certutil
tool.
3. Copy the PKCS #10 ASCII output to a text file.
4. Run the CMCEnroll utility.
For example, if the input file called
request34.txt
, the agent certificate is stored in the
directory
/var/lib/pki-ca/alias
, the certificate common name of the agent certificate is
CertificateManagerAgentsCert
, and the password for the certificate database is
secret
,
the command is as follows:
CMCEnroll -d "/var/lib/pki-ca/alias" -n "CertificateManagerAgentsCert" -r /export/
requests/request34.txt -p secret
The output of this command is stored in a file with the same filename with
.out
appended to the
filename.
5. Submit the signed certificate through the end-entities page.
a. Open the end-entities page.
http
s
://server.example.com:
9444/ca/ee/ca
b. Select the CMC enrollment form from the list of certificate profiles.
c. Paste the content of the output file into the
Certificate Request
text area of this form.
d. Remove
-----BEGIN NEW CERTIFICATE REQUEST-----
and
----END NEW
CERTIFICATE REQUEST-----
from the pasted content.
e. Fill in the contact information, and submit the form.
6. The certificate is immediately processed and returned.
7. Use the agent page to search for the new certificate.
9.4. Testing Enrollment
For information on testing enrollment through the profiles, see
Chapter 2, Making Rules for Issuing
Certificates
. To test whether end users can successfully enroll for a certificate using the authentication
method set:
1. Open the end-entities page.
http
s
://server.example.com:
9444/ca/ee/ca
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...