Chapter 2. Making Rules for Issuing Certificates
44
Profile ID
Profile Name
Description
NOTE
Renewal profiles
can only be used
in conjunction with
the profile that
issued the original
certificate. There
are two settings
that are beneficial:
• It is important
the the original
enrollment profile
name does not
change.
• The Renew
Grace Period
Constraint
should be set
in the original
enrollment
profile. This
defines the
amount of time
before and after
the certificate's
expiration date
when the user is
allowed to renew
the certificate.
There are only
a few examples
of these in the
default profiles,
and they are
mostly not
enabled by
default.
caOCSPCert
Manual OCSP Manager
Signing Certificate Enrollment
Enrolls OCSP Manager
certificates.
caOtherCert
Other Certificate Enrollment
Enrolls other certificates.
caRAagentCert
RA Agent-Authenticated Agent
User Certificate Enrollment
Enrolls RA agent user
certificates with RA agent
authentication.
caRACert
Manual Registration Manager
Signing Certificate Enrollment
Enrolls Registration Manager
certificates.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...