Manuals database logo
manualsdatabase
Your AI-powered manual search engine

Netscape Certificate Management System 6.0 manuals

Certificate Management System 6.0 first page preview

Certificate Management System 6.0

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. Table Of Contents
  7. Table Of Contents
  8. Table Of Contents
  9. Table Of Contents
  10. Table Of Contents
  11. Table Of Contents
  12. Table Of Contents
  13. Table Of Contents
  14. Table Of Contents
  15. Table Of Contents
  16. Table Of Contents
  17. Table Of Contents
  18. Table Of Contents
  19. Table Of Contents
  20. About This Guide
  21. What You Should Already Know
  22. Conventions Used in This Guide
  23. Where to Go for Related Information
  24. Part 1 Overview and Demo Installation
  25. Overview of Key Features
  26. Flexible end-entity registration services framework
  27. System Overview
  28. Public-Key Infrastructure
  29. CMS Subsystems or Managers
  30. Certificate Manager
  31. Registration Manager
  32. Data Recovery Manager
  33. Online Certificate Status Manager
  34. Basic System Configuration
  35. Plug-in Modules
  36. Policy Plug-in Modules
  37. Job Plug-In Modules
  38. Mapper and Publisher Plug-in Modules
  39. Event-Driven Notifications
  40. Command-Line Utilities
  41. Entry Points for Various Types of Users
  42. Agent Services Interface
  43. Registration Manager Agent Services
  44. Data Recovery Manager Agent Services
  45. Online Certificate Status Manager Agent Services Interface
  46. End-Entity Services Interface
  47. System Architecture
  48. JSS and the Java/JNI Layer
  49. Authentication and Policy Modules
  50. Security and Directory Protocols
  51. Some Enrollment Scenarios
  52. Extranet/E-Commerce: ExampleCorp
  53. Enrolling Existing Customers
  54. Enrolling New Customers
  55. Enrolling Extranet Users
  56. PIN Registration: Atlas Manufacturing
  57. VPN Client Enrollment and Revocation
  58. Router Enrollment and Revocation
  59. End Entities and Life-Cycle Management
  60. Access to Subsystems
  61. HTML Forms for End Users
  62. Netscape Personal Security Manager
  63. System Requirements
  64. Overview of the Default Demo
  65. Demo Passwords
  66. Installing the Default Demo
  67. Step 2. Run the Installation Wizard
  68. Step 3. Get the First User Certificate
  69. If You Need the First Agent Form Again
  70. Using the Default Demo
  71. Viewing Issued Certificates From the Agent Gateway
  72. Enrolling for a Certificate From the End-Entity Gateway
  73. Finding and Approving a Certificate Request
  74. Setting Your Browser to Use the Agent Certificate
  75. Create a Policy
  76. Use an LDAP Directory
  77. Step 1. Enable Directory-Based Authentication
  78. Step 2. Add a User to the Directory
  79. Step 3. Enroll with Directory-Based Authentication
  80. Publish Certificates to an LDAP Directory
  81. Configure the Publishing Destination
  82. Set Rules for Publishing Certificates
  83. Update the Publishing Directory
  84. Send Renewal Reminders
  85. Configuring a Mail Server for Certificate Management System
  86. Configuring Certificate Management System to Send Renewal Reminders
  87. Part 2 Planning and Installation
  88. Topology Decisions
  89. Certificate Manager and Registration Manager
  90. Certificate Manager and Data Recovery Manager
  91. Certificate Manager, Data Recovery Manager, and Registration Manager
  92. Cloned Certificate Manager
  93. CA's Distinguished Name
  94. CA Signing Certificate's Validity Period
  95. CAs and Certificate Extensions
  96. Cryptographic Token Decisions
  97. Publishing Decisions
  98. Publishing CRLs to the Online Certificate Status Manager
  99. Subsystem Certificate Decisions
  100. Certificate Manager Certificates
  101. Data Recovery Manager Certificate and Storage Key
  102. Authentication Decisions
  103. Information for UNIX Installation Script
  104. User/Group Directory Server
  105. Administration Server Information
  106. Certificate Management System Identifier
  107. Configuration Directory Settings
  108. Administration Server Port
  109. Token Logon or Single Sign-On Password
  110. Subsystems
  111. Network Configuration
  112. Key-Pair Information for CA Signing Certificate
  113. Validity Period for CA Signing Certificate
  114. CA Signing Certificate Request
  115. Subject Name for Registration Manager Signing Certificate
  116. Registration Manager Signing Certificate Issuer
  117. Subject Name for Transport Certificate
  118. Validity Period for Transport Certificate
  119. Transport Certificate Request
  120. Online Certificate Status Manager Configuration
  121. Online Certificate Status Manager Signing Certificate Request
  122. Online Certificate Status Manager Signing Certificate Issuer
  123. CA Signing Certificate
  124. SSL Server Key and Certificate
  125. Subject Name for SSL Server Certificate
  126. Extensions for SSL Server Certificate
  127. SSL Certificate Request
  128. Installation Overview
  129. Installation Stages
  130. Before You Begin the Installation
  131. Stage 1. Running the Installation Script
  132. Running the Installation Script on Windows NT
  133. Stage 2. Running the Installation Wizard
  134. Installing the Certificate Manager as a Root CA
  135. Installing the Certificate Manager as a Subordinate CA
  136. Installing a Standalone Registration Manager
  137. Installing a Standalone Data Recovery Manager
  138. Installing a Online Certificate Status Manager
  139. Stage 3. Enrolling for Administrator/Agent Certificate
  140. Agent Certificate for Other CMS Managers
  141. Stage 5. Creating Additional Instances or CA Clones
  142. Installing Multiple CMS Instances
  143. Cloning a Certificate Manager
  144. Step 1. Before You Begin
  145. Step 2. Create Instances for Clone CAs
  146. Installing Clone CA in a Different Server Group
  147. Installing Clone CA on a Separate Host
  148. Step 4. Copy Master CA's Certificate and Key Database
  149. Step 6. Configure the Clone CA
  150. Step 8. Establish Trust Between Master CA and Clone CAs
  151. Step B. Create a Privileged-User Entry for Clone CAs
  152. Step 9. Test Clone-Master Connection
  153. Step B. Approve the Request
  154. Step D. Revoke the Certificate
  155. Step 10. Use Master CA's Agent Certificate in Clone CAs
  156. Viewing Instance Information
  157. Changing the Name of an Instance
  158. Removing an Instance From a System
  159. Uninstalling Certificate Management System
  160. Uninstalling by Using the Windows NT Add/Remove Programs Utility
  161. Significance of password.conf File
  162. Required Start-up Information
  163. Starting From Netscape Console
  164. Starting From the Command Line
  165. Starting From the Windows NT Services Panel
  166. Stopping From Netscape Console
  167. Stopping From the Command Line
  168. Restarting From the CMS Window
  169. Restarting From the Command Line
  170. Attending to an Unresponsive Server
  171. Password-Quality Checker
  172. Part 3 Configuration
  173. Netscape Console
  174. Users and Groups Tab
  175. Netscape Administration Server
  176. Starting Administration Server
  177. Shutting Down Administration Server
  178. The CMS Window
  179. Tasks Tab
  180. Logging In to the CMS Window
  181. Effects of Installation Type on Configuration
  182. Duplicating Configuration From One Instance to Another
  183. Modifying the Configuration
  184. Guidelines for Editing the Configuration File
  185. Sample Configuration File
  186. Road Map to Configuring Subsystems
  187. Step 1. Check Which Subsystem is Installed in the Instance
  188. Step 5. Customize End-Entity and Agent Forms
  189. Step 8. Schedule Jobs
  190. Step 11. Set up Key Archival and Recovery
  191. Chapter 11 Setting Up Ports
  192. Remote Administration Port
  193. Agent Port
  194. Step 1. Specify the Port Number
  195. Step 2: Specify IP Addresses
  196. Internal Database
  197. Step 1. Identify the Directory Server Instance
  198. Step 2. Restrict Access to the Internal Database
  199. Privileged-User Types and Responsibilities
  200. Agents
  201. Agent's Certificate for SSL Client Authentication
  202. Revocation Status Checking of Agent Certificates
  203. Trusted Managers
  204. Subsystems That Can Function as Trusted Managers
  205. Connectors for Linking Trusted Managers
  206. Trusted Manager's Certificate for SSL Client Authentication
  207. Groups and Their Privileges
  208. Groups for Agents
  209. Group for Registration Manager Agents
  210. Group for Online Certificate Status Manager Agents
  211. Setting Up Privileged Users
  212. Setting Up Agents
  213. Setting up Agents Using the Manual Process
  214. Setting Up Trusted Managers
  215. Setting Up a Registration Manager as a Trusted Manager
  216. Setting Up a Certificate Manager as a Trusted Manager
  217. Changing Privileged-User Information
  218. Changing a Privileged User's Certificate
  219. Changing Members in a Group
  220. Deleting a Privileged User
  221. Keys and Certificates for the Main Subsystems
  222. Certificate Manager's Key Pairs and Certificates
  223. OCSP Signing Key Pair and Certificate
  224. CRL Signing Key Pair and Certificate
  225. SSL Server Key Pair and Certificate
  226. Registration Manager's Key Pairs and Certificates
  227. Data Recovery Manager's Key Pairs and Certificates
  228. Transport Key Pair and Certificate
  229. Online Certificate Status Manager's Key Pairs and Certificates
  230. Tokens for Storing CMS Keys and Certificates
  231. External Token
  232. Managing Tokens Used by the Subsystems
  233. Changing a Token's Password
  234. Hardware Cryptographic Accelerators
  235. Using the Wizard to Request a Certificate
  236. Step 1. Select the Operation
  237. Step 2. Choose the Certificate
  238. Step 3. Specify the Key-Pair Information
  239. Step 4. Specify the Subject Name for the Certificate
  240. Step 5. Specify the Validity Period
  241. Step 6. Specify Extensions
  242. Step 7. Copy the Certificate Signing Request
  243. Step 8. Check the Certificate Request Status
  244. Using the Wizard to Install a Certificate or Certificate Chain
  245. Data Formats for Installing Certificates and Certificate Chains
  246. Step 2. Select the Certificate or Certificate Chain
  247. Step 3. Specify the Location of the Certificate
  248. Step 4. View the Certificate or Certificate Chain
  249. Step 6. Verify the Certificate Status
  250. Step 1. Get the Required SSL Server Certificates
  251. Getting an SSL Client Certificate for a Subsystem
  252. Setting Up Cipher Preferences for SSL Communications
  253. SSL Ciphers Supported in Certificate Management System
  254. Configuring the Server to Use Specific Ciphers
  255. Getting New Certificates for the Subsystems
  256. Step 1. Plan for the New Certificate
  257. Step 2. Request the New Certificate
  258. Step 4. Deploy the New Certificate
  259. Deploying Registration Manager's Signing Certificate
  260. Deploying Data Recovery Manager's Transport Certificate
  261. Deploying a Subsystem's SSL Server Certificate
  262. Renewing Certificates for the Subsystems
  263. Step 1. Plan for Certificate Renewal
  264. Step 2. Renew the Existing Certificate
  265. Step 3. Install the Renewed Certificate
  266. Deploying Certificate Manager's Renewed CA Signing Certificate
  267. Deploying Data Recovery Manager's Renewed Transport Certificate
  268. Deploying a Subsystem's Renewed SSL Server Certificate
  269. Step 5. Restart the Server
  270. Viewing the Certificate Database Content
  271. Changing the Trust Settings of a CA Certificate
  272. Installing a New CA Certificate in the Certificate Database
  273. Introduction to Authentication
  274. Privileged-User Authentication
  275. Authentication of Agents
  276. End-Entity Authentication
  277. Authentication of End Users During Certificate Revocation
  278. Configuring Authentication for End-User Enrollment
  279. Step 2. Set Up the Directory for PIN-Based Enrollment
  280. Step B. Update the Directory
  281. Step C. Prepare the Input File
  282. Step E. Check the Output File
  283. Step 4: Add an Authentication Instance
  284. Step 5. Set Up the Enrollment Interface
  285. Step B. Customize the Form
  286. Step D. Remove Unwanted Enrollment Options
  287. Step 6. Enable End-Entity Interaction
  288. Enabling End-Entity Interaction with a Registration Manager
  289. Step 7. Turn on Automated Notification
  290. Step 9. Deliver PINs to End Users
  291. Managing Authentication Instances
  292. Modifying an Authentication Instance
  293. Managing Authentication Plug-in Modules
  294. Deleting an Authentication Module
  295. Automated Notifications
  296. Notifications of Certificate Issuance to End Entities
  297. Notification of New Request in Queue
  298. Customizing Notification Messages
  299. Customizing Message Templates
  300. Tokens Available in Message Templates
  301. Tokens for Rejection Notifications to End Entities
  302. Tokens for Request In Queue Notification Messages
  303. Step 2. Turn On Certificate-Issuance Notification
  304. Step 3. Turn on Request in Queue Notification
  305. Step 4. Verify Mail Server Settings
  306. Step 5. Test Your Configuration
  307. Configuring a Subsystem to Run Automated Jobs
  308. Step 2. Modify Existing Jobs
  309. Step 3. Delete Unwanted Jobs
  310. Step 5. Schedule the Frequency
  311. Step 7. Test Your Configuration
  312. Registering a Job Module
  313. Deleting a Job Module
  314. Introduction to Policy
  315. What Is Policy
  316. Policy Rules
  317. Using Predicates in Policy Rules
  318. Attributes for Predicates
  319. Policy Processor
  320. Configuring Policy Rules for a Subsystem
  321. Step 2. Modify Existing Policy Rules
  322. Step 3. Delete Unwanted Policy Rules
  323. Step 5. Reorder Policy Rules
  324. Step 6. Restart the Server
  325. Using JavaScript for Policies
  326. Deleting a Policy Module
  327. Publishing of Certificates to a Directory
  328. Timing of Directory Updates
  329. Directory Update Process
  330. Directory Synchronization
  331. What's a CRL
  332. Reasons for Revoking a Certificate
  333. Revocation Checking by Netscape Clients
  334. Publishing of CRLs to an LDAP Directory
  335. CRL Issuing Points
  336. Step 2. Set Up the Directory for Publishing
  337. Step C. Identify an Entry That Has Write Access
  338. Step E. Specify the Directory Authentication Method
  339. Step F. Modify the Certificate Mapping File
  340. Step G. Restart Directory Server
  341. Step B. Add Mappers, Publishers, and Publishing Rules
  342. Step 4. Configure the Certificate Manager to Publish CRLs
  343. Step A. Specify CRL Details
  344. Step B. Set the CRL Extensions
  345. Step C. Create a Mapper for the CRL
  346. Step D. Create a Publisher for the CRL
  347. Step E. Create a Publishing Rule for the CRL
  348. Step 5. Identify the Publishing Directory
  349. Step 6. Test Certificate and CRL Publishing
  350. Step A. Decide a Directory Entry for Requesting a Certificate
  351. Step D. Download the Certificate to the Browser
  352. Step F. Revoke the Certificate
  353. Step G. Check the Directory for the CRL
  354. Manually Updating Certificates in the Directory
  355. Manually Updating the CRL in the Directory
  356. Configuring Certificate Manager to Publish to Files
  357. Step 2. Configure the Certificate Manager
  358. Step B. Create Publishing Rules for Certificates
  359. Step C. Create a Publishing Rule for CRLs
  360. Step D. Specify CRL Details
  361. Step E. Set the CRL Extensions
  362. Step F. Make Sure Publishing is Enabled
  363. Step D. Check the File for the Certificate
  364. Step E. Revoke the Certificate
  365. Step F. Check the File for the CRL
  366. Managing Mapper and Publisher Plug-in Modules
  367. Deleting a Mapper or Publisher Module
  368. What's an OCSP-Compliant PKI Setup
  369. How to Get an OCSP Responder
  370. How Online Certificate Status Manager Works
  371. How to Get OCSP-Compliant Clients
  372. Setting Up a Certificate Manager with OCSP Service
  373. Step 2. Install OCSP-Compliant Client
  374. Setting Up Personal Security Manager for OCSP-Based Certificate Validation
  375. Step 3. Enable Certificate Manager's HTTP Port
  376. Step 5. Restart the Certificate Manager
  377. Step A. Turn On Revocation Checking in the Browser
  378. Step C. Approve the Request
  379. Step E. Make Sure the CA is Trusted by the Browser
  380. Step H. Revoke the Certificate
  381. Step J. Check the Certificate Manager's OCSP Service Status Again
  382. Step 2. Install an OCSP-Compliant Client
  383. Step A. Specify CRL Format and Publishing Interval
  384. Step C. Create a Publisher for the CRL
  385. Step D. Create a Publishing Rule for the CRL
  386. Step E. Make Sure Publishing is Enabled
  387. Step 5. Configure Certificate Manager for Required Extension Policies
  388. Step 6. Configure the Online Certificate Status Manager
  389. Step 7. Restart the Certificate Manager
  390. Step 8. Restart the Online Certificate Status Manager
  391. Step 10. Test Your OCSP Responder Setup
  392. Step B. Request a Certificate
  393. Step F. Verify the Certificate in the Browser
  394. Step I. Verify the Certificate in the Browser
  395. PKI Setup for Key Archival and Recovery
  396. Clients That Can Generate Dual Key Pairs
  397. Forms for Users and Key Recovery Agents
  398. Where the Keys are Stored
  399. How Key Archival Works
  400. Key Recovery Process
  401. Interface for the Key Recovery Process
  402. Local Versus Remote Key Recovery Authorization
  403. How Agent-Initiated Key Recovery Works
  404. Key Recovery Agent Scheme
  405. Changing Key Recovery Agents' Passwords
  406. Configuring Key Archival and Recovery Process
  407. Step A. Deploy Clients That Can Generate Dual Key Pairs
  408. Step C. Customize the Certificate Enrollment Form
  409. Step D. Configure Key Archival Policies
  410. Step 2. Set Up the Key Recovery Process
  411. Step B. Facilitate the Key Recovery Agents to Change the Passwords
  412. Step 3. Test Your Key Archival and Recovery Setup
  413. Step B. Verify the Key
  414. Step D. Restore the Key in the Browser's Database
  415. Introduction to Logs
  416. Logs Maintained by the Server
  417. Services That Are Logged
  418. Log Levels (Message Categories)
  419. Log File Locations
  420. Log File Naming Conventions
  421. Rotation of Log Files
  422. Location of Rotated Log Files
  423. Configuring CMS Logs
  424. Step 3. Delete Unwanted Listeners
  425. Step 4. Create New Listeners
  426. Monitoring CMS Logs
  427. Monitoring System Logs
  428. Monitoring Error Logs
  429. Monitoring Audit Logs
  430. Using System Tools for Monitoring the Server (Windows NT Only)
  431. Logging to Windows NT Event Log
  432. Avoiding Event Log From Getting Filled
  433. Archiving of Rotated Log Files
  434. Signing Log Files
  435. Managing Log Modules
  436. Deleting a Log Module
  437. Part 4 Issuing and Managing Certificates
  438. Certificate Issuance to Servers
  439. How the Manual Server Enrollment Process Works
  440. Getting Server SSL Certificates for Netscape Servers
  441. Step 1. Generate the Server Certificate Request
  442. Step 3. Install Your Server's SSL Certificate
  443. Step 5. Verify Your Server's SSL and CA Certificates
  444. Renewal of Server Certificates
  445. CEP Enrollment
  446. Setting up CEP Enrollment Manually
  447. Step 1. Set up the Directory for Publishing Certificates and CRLs
  448. Step 2. Configure the Certificate Manager for Publishing Certificates and CRLs
  449. Step 3. Set Up Automated Enrollment
  450. Step 4. Set Up Multiple CEP Services
  451. Certificate Issuance to Routers or VPN Clients
  452. Step 2. Generate the Key Pair for the Router
  453. Step 3. Request the CA's Certificate
  454. Example
  455. Part 5 Appendix
  456. Data Formats
Certificate Management System 6.0 first page preview

Certificate Management System 6.0

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. About This Guide
  7. What's in This Guide
  8. Conventions Used in This Guide
  9. Where to Go for Related Information
  10. Location
  11. Syntax
  12. Listing the Contents of the Password Cache
  13. Changing the Password of an Entry in the Password Cache
  14. Deleting an Entry From the Password Cache
  15. Usage
  16. Locating the PIN Generator Tool
  17. The setpin Command
  18. Example
  19. How the Tool Works
  20. Input File
  21. Output File
  22. How PINs Are Stored in the Directory
  23. Chapter 5 Extension Joiner Tool
  24. Backing Up Data
  25. What the Backup Tool Does Not Do
  26. After You Finish a Backup
  27. Restoring Data
  28. Running the Restore Tool
  29. Chapter 9 Pretty Print Certificate Tool
  30. Options and Arguments
  31. Examples
  32. Listing Certificates in a Database
  33. Creating a Certificate
  34. Validating a Certificate
  35. Creating a Key Database
  36. Generating a New Key
  37. Displaying Public Key Information
  38. Introduction to Netscape Signing Tool
  39. What Is Netscape Signing Tool
  40. JAR Format and JAR Archives
  41. What Signing a File Means
  42. Using Netscape Signing Tool
  43. Getting Ready to Use Netscape Signing Tool
  44. Listing Available Certificates
  45. Signing a File
  46. Using Netscape Signing Tool with a ZIP Utility
  47. SignTool Syntax and Options
  48. Command File Syntax
  49. Generating Test Object-Signing Certificates
  50. Using Netscape Signing Tool with Smart Cards
  51. Using the -M Option to List Smart Cards
  52. Using FIPS-140 Mode
  53. Verifying FIPS Mode
  54. Answers to Common Questions
  55. Description
  56. Options
  57. Example 1
  58. Example 2
  59. Example 3
  60. Example 4
  61. Usage Tips
  62. Restricting Ciphers
  63. JAR Installation File
  64. Script Grammar
  65. Keys
  66. Per-Platform Keys
  67. Per-File Keys
  68. Creating Database Files
  69. Setting a Default Provider
  70. Enabling a Slot
  71. Adding a Cryptographic Module
Certificate Management System 6.0 first page preview

Certificate Management System 6.0

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. About This Guide
  7. Conventions Used in This Guide
  8. Where to Go for Related Information
  9. What You Need to Know to Change Forms
  10. HTTP, Query URLs, and HTML Forms
  11. Requests Sent to the CMS server
  12. Errors and the Error Template
  13. JavaScript Used By All Interfaces
  14. How Client Type Determines the End-Entity Interface
  15. Accessing the End-Entity Services Interface
  16. Forms for Certificate Enrollment
  17. Forms for Certificate Renewal
  18. Forms for Certificate Retrieval
  19. Forms for Key Recovery
  20. Output Templates for End-Entity Interfaces
  21. Overview of End-Entity Interfaces
  22. Certificate Enrollment Protocol Interface
  23. Challenge Revocation Interface
  24. Response
  25. Display Certificate From Request Interface
  26. Request Parameters
  27. Enrollment Interface
  28. Default Forms
  29. Get CA Chain Interface
  30. Get Certificate By Serial Number Interface
  31. Get Certificate From Request Interface
  32. Get CRL Interface
  33. List Certificates Interface
  34. Renewal Interface
  35. Revocation Interface
  36. Chapter 4 Internationalization of End-Entity Interface
  37. Agent Services Interface
  38. Certificate Manager Agent Services
  39. Registration Manager Agent Services
  40. Data Recovery Manager Agent Services
  41. Agent Forms and Templates
  42. Locating Agent Forms and Templates
  43. Overview of Agent Interfaces
  44. Approve Revocation Interface
  45. Bulk Enrollment Interface
  46. Configuration Parameters
  47. Display Key By Serial Number Interface
  48. Display Key For Recovery Interface
  49. Examine Recovery Interface
  50. Get Approval Status Interface
  51. Get PKCS #12 Data Interface
  52. Grant Recovery Interface
  53. Key Query Interface
  54. Key Recovery Query Interface
  55. Process Certificate Request Interface
  56. Process DRM Request Interface
  57. Process Request Interface
  58. Recover Key By Serial Number Interface
  59. Remove Certificate Hold Interface
  60. Requests Query Interface
  61. Select for Revocation Interface
  62. Update CRL Interface
  63. Update Directory Interface
Certificate Management System 6.0 first page preview

Certificate Management System 6.0

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. Table Of Contents
  7. Table Of Contents
  8. About This Guide
  9. What You Should Already Know
  10. Conventions Used in This Guide
  11. Where to Go for Related Information
  12. Overview of Authentication Modules
  13. Manual Authentication
  14. UidPwdDirAuth Plug-in Module
  15. Configuration Parameters of UidPwdDirAuth
  16. UidPwdPinDirAuth Plug-in Module
  17. Configuration Parameters of UidPwdPinDirAuth
  18. NISAuth Plug-in Module
  19. Configuration Parameters of NISAuth
  20. PortalEnroll Plug-in Module
  21. Configuration Parameters of PortalAuth
  22. Certificate-Based Enrollment
  23. Enrollment Forms
  24. Customizing Enrollment Forms for Generating DSA Key Pairs
  25. Generating Files Required By Third-Party Object Signing Tools
  26. RenewalNotificationJob Plug-in Module
  27. Configuration Parameters of RenewalNotificationJob
  28. RequestInQJob Plug-in Module
  29. Configuration Parameters of RequestInQJob
  30. UnpublishExpiredJob Plug-in Module
  31. Configuration Parameters of UnpublishExpiredJob
  32. Schedule for Executing Jobs
  33. Customizing Notification Messages
  34. Customizing Message Templates
  35. Tokens for Request In Queue Notification Messages
  36. Overview of Constraints-Specific Policy Modules
  37. AttributePresentConstraints Plug-in Module
  38. Configuration Parameters of AttributePresentConstraints
  39. DSAKeyConstraints Plug-in Module
  40. Configuration Parameters of DSAKeyConstraints
  41. DSAKeyRule Rule
  42. Configuration Parameters of IssuerConstraints
  43. IssuerRule Rule
  44. KeyAlgorithmConstraints Plug-in Module
  45. KeyAlgRule Rule
  46. Configuration Parameters of RenewalConstraints
  47. RenewalConstraintsRule Rule
  48. RenewalValidityConstraints Plug-in Module
  49. Configuration Parameters of RenewalValidityConstraints
  50. DefaultRenewalValidityRule Rule
  51. RevocationConstraints Plug-in Module
  52. RevocationConstraintsRule Rule
  53. RSAKeyConstraints Plug-in Module
  54. RSAKeyRule Rule
  55. SigningAlgorithmConstraints Plug-in Module
  56. Configuration Parameters of SigningAlgorithmConstraints
  57. SigningAlgRule Rule
  58. Configuration Parameters of SubCANameConstraints
  59. SubCANameConstraints Rule
  60. UniqueSubjectNameConstraints Plug-in Module
  61. UniqueSubjectNameConstraints Rule
  62. Configuration Parameters of ValidityConstraints
  63. Overview of Extension-Specific Policy Modules
  64. AuthInfoAccessExt Plug-in Module
  65. Configuration Parameters of AuthInfoAccessExt
  66. AuthInfoAccessExt Rule
  67. AuthorityKeyIdentifierExt Plug-in Module
  68. Configuration Parameters of AuthorityKeyIdentifierExt
  69. AuthorityKeyIdentifierExt Rule
  70. Configuration Parameters of BasicConstraintsExt
  71. BasicConstraintsExt Rule
  72. CertificatePoliciesExt Plug-in Module
  73. Configuration Parameters of CertificatePoliciesExt
  74. CertificatePoliciesExt Rule
  75. CertificateRenewalWindowExt Plug-in Module
  76. Configuration Parameters of CertificateRenewalWindowExt
  77. CertificateScopeOfUseExt Plug-in Module
  78. Configuration Parameters of CertificateScopeOfUseExt
  79. CRLDistributionPointsExt Plug-in Module
  80. CRLDistributionPointsExt Rule
  81. ExtendedKeyUsageExt Plug-in Module
  82. Configuration Parameters of ExtendedKeyUsageExt
  83. CODESigningExt Rule
  84. OCSPSigningExt Rule
  85. GenericASN1Ext Plug-in Module
  86. Configuration Parameters of GenericASN1Ext
  87. GenericASN1Ext Rule
  88. Configuration Parameters of IssuerAltNameExt
  89. KeyUsageExt Plug-in Module
  90. Configuration Parameters of KeyUsageExt
  91. CMCertKeyUsageExt Rule
  92. RMCertKeyUsageExt Rule
  93. ServerCertKeyUsageExt Rule
  94. ClientCertKeyUsageExt Rule
  95. ObjSignCertKeyUsageExt Rule
  96. CRLSignCertKeyUsageExt
  97. Configuration Parameters of NameConstraintsExt
  98. NameConstraintsExt Rule
  99. NSCCommentExt Plug-in Module
  100. Configuration Parameters of NSCCommentExt
  101. NSCCommentExt Rule
  102. NSCertTypeExt Plug-in Module
  103. Configuration Parameters of NSCertTypeExt
  104. NSCertTypeExt Rule
  105. Configuration Parameters of OCSPNoCheckExt
  106. OCSPNoCheckExt Rule
  107. PolicyConstraintsExt Plug-in Module
  108. PolicyConstraintsExt Rule
  109. Configuration Parameters of PolicyMappingsExt
  110. PolicyMappingsExt Rule
  111. Configuration Parameters of PrivateKeyUsagePeriodExt
  112. RemoveBasicConstraintsExt Plug-in Module
  113. Configuration Parameters of RemoveBasicConstraintsExt
  114. SubjectAltNameExt Plug-in Module
  115. Configuration Parameters of SubjectAltNameExt
  116. SubjectAltNameExt Rule
  117. SubjectDirectoryAttributesExt Plug-in Module
  118. Configuration Parameters of SubjectDirectoryAttributesExt
  119. SubjectKeyIdentifierExt Plug-in Module
  120. Configuration Parameters of SubjectKeyIdentifierExt
  121. Overview of Mapper Modules
  122. LdapCaSimpleMap Plug-in Module
  123. Configuration Parameters of LdapCaSimpleMap
  124. LdapCaCertMap Mapper
  125. Configuration Parameters of LdapDNCompsMap
  126. LdapDNExactMap Plug-in Module
  127. LdapSimpleMap Plug-in Module
  128. Configuration Parameters of LdapSimpleMap
  129. LdapUserCertMap Mapper
  130. Configuration Parameters of LdapSubjAttrMap
  131. Overview of Publisher Modules
  132. FileBasedPublisher Plug-in Module
  133. LdapCaCertPublisher Plug-in Module
  134. Configuration Parameters of LdapCaCertPublisher
  135. LdapCaCertPublisher Publisher
  136. Configuration Parameters of LdapUserCertPublisher
  137. LdapUserCertPublisher Publisher
  138. Configuration Parameters of LdapCrlPublisher
  139. LdapCrlPublisher Publisher
  140. Overview of CRL Extension Modules
  141. AuthorityKeyIdentifier Rule
  142. CRLNumber Rule
  143. CRLReason Rule
  144. HoldInstruction Rule
  145. InvalidityDate Rule
  146. IssuerAlternativeName Rule
  147. Overview of Log Modules
  148. file Plug-in Module
  149. Configuration Parameters of file
  150. Audit Log Event Listener
  151. Error Log Event Listener
  152. System Log Event Listener
  153. Configuration Parameters of NTEventLog
  154. NTSystem Event Listener
  155. What Is a Distinguished Name
  156. Distinguished Name Components
  157. Root Distinguished Name
  158. DNs in Certificate Management System
  159. Extending Attribute Support
  160. Adding New or Proprietary Attributes
  161. Adding Attributes to an Enrollment Form
  162. Changing the DER Encoding Order
  163. Role of Distinguished Names in Certificates
  164. DNs in End-Entity Certificates
  165. Selecting DNs for Certificates
  166. Appendix B Object Identifiers
  167. Introduction to Certificate Extensions
  168. Structure of Certificate Extensions
  169. Sample Certificate Extensions
  170. Standard X.509 v3 Certificate Extensions
  171. authorityInfoAccess
  172. authorityKeyIdentifier
  173. basicConstraints
  174. certificatePolicies
  175. cRLDistributionPoints
  176. extKeyUsage
  177. issuerAltName
  178. keyUsage
  179. nameConstraints
  180. OCSPNocheck
  181. policyConstraints
  182. policyMappings
  183. subjectAltName
  184. subjectDirectoryAttributes
  185. Introduction to CRL Extensions
  186. Structure of CRL Extensions
  187. Sample CRL and CRL Entry Extensions
  188. Standard X.509 v3 CRL Extensions
  189. CRLNumber
  190. deltaCRLIndicator
  191. issuingDistributionPoint
  192. CRL Entry Extensions
  193. holdInstructionCode
  194. reasonCode
  195. netscape-cert-type
Netscape categories
Server
Software
Gateway
More Netscape categories
Manuals database logo
manualsdatabase
Your AI-powered manual search engine