Admin Guide
iv
2.3.1. Default RA Profiles .................................................................................. 48
2.3.2. Creating RA Enrollment Forms ................................................................. 48
2.3.3. Configuring the Request Queues .............................................................. 50
2.4. Managing Smart Card CA Profiles ....................................................................... 53
2.4.1. Editing Enrollment Profiles for the TPS ..................................................... 54
2.4.2. Creating Custom TPS Profiles .................................................................. 54
2.4.3. Using the Windows Smart Card Logon Profile ........................................... 55
2.5. Setting the Signing Algorithms for Certificates ...................................................... 55
2.5.1. Setting the CA's Default Signing Algorithm ................................................ 55
2.5.2. Setting the Signing Algorithm Default in a Profile ....................................... 56
2.6. Managing CA-Related Profiles ............................................................................ 58
2.6.1. Setting Restrictions on CA Certificates ..................................................... 58
2.6.2. Changing the Restrictions for CAs on Issuing Certificates ........................... 59
2.7. Managing Subject Names and Subject Alternative Names ..................................... 61
2.7.1. Inserting LDAP Directory Attribute Values and Other Information into the
Subject Alt Name .............................................................................................. 61
2.7.2. Changing DN Attributes in CA-Issued Certificates ...................................... 64
2.7.3. Customizing the Subject DN in a Certificate Request Issued by an RA ......... 67
3. Setting up Key Archival and Recovery 69
3.1. About Key Archival and Recovery ....................................................................... 69
3.2. Setting up Key Archival ...................................................................................... 70
3.3. Setting up Agent-Approved Key Recovery Schemes ............................................. 72
3.4. Testing the Key Archival and Recovery Setup ...................................................... 73
4. Requesting, Enrolling, and Managing Certificates 75
4.1. About Enrolling and Renewing Certificates ........................................................... 75
4.2. Configuring Internet Explorer to Enroll Certificates ................................................ 75
4.3. Requesting and Receiving Certificates ................................................................. 77
4.3.1. Requesting and Receiving a User or Agent Certificate through the End-
Entities Page .................................................................................................... 77
4.3.2. Requesting Certificates Using certutil ........................................................ 81
4.4. Enrolling a Certificate on a Cisco Router ............................................................. 85
4.4.1. Configuring a Router for SCEP Enrollment ................................................ 86
4.4.2. Generating the SCEP Certificate for a Router ............................................ 86
4.4.3. Working with Subordinate CAs ................................................................. 89
4.4.4. Re-enrolling a Router ............................................................................... 90
4.4.5. Enabling Debugging ................................................................................. 90
4.5. Performing Bulk Issuance ................................................................................... 90
4.5.1. Creating the Bulk Issuance File ................................................................ 91
4.5.2. Running the Bulk Issuance Command ....................................................... 92
4.6. Configuring and Using the Auto Enrollment Proxy ................................................. 93
4.6.1. About Auto Enrollment ............................................................................. 93
4.6.2. Installing and Setting up the Auto Enrollment Proxy ................................... 98
4.6.3. Managing Auto Enrollment Proxy Settings ............................................... 109
4.6.4. Manually Requesting Domain Certificates ................................................ 112
4.7. Renewing Certificates ....................................................................................... 116
4.7.1. About Renewal ...................................................................................... 116
4.7.2. Creating Custom Renewal Profiles .......................................................... 119
4.7.3. Renewing Certificates ............................................................................ 121
5. Using and Configuring the Token Management System: TPS, TKS, and Enterprise
Security Client 127
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...