12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Certificate Name Filtering SupportSearch Sequence ScenarioAssume the following records exist <strong>and</strong> all are trusted. They are listed in the order inwhich they are grouped in the search table.CERTMAP(MAP001) ACID(NJDEPT1)IDNFILTR(OU=Verisign Class 1 Individual Subscriber.O=Verisign,Inc.L=Internet)SDNFILTR(OU=DEPT1.OU=NJ.OU=Sales.O=ABC Co)CERTMAP(MAP002) ACID(NJDEPTX)IDNFILTR(O=Verisign,Inc.L=Internet) SDNFILTR(OU=Sales.O=ABC Co)CERTMAP(MAP003) ACID(NYDEPT2)SDNFILTR(OU=DEPT2.OU=NY,OU=Sales.O=ABC Co)CERTMAP(MAP004) ACID(NYDEPT3)SDNFILTR(OU=DEPT3.OU=NY,OU=Sales.O=ABC Co)CERTMAP(MAP005) ACID(ABCDEPT)SDNFILTR(OU=Sales.O=ABC Co)CERTMAP(MAP006) ACID(ABCTECH)SDNFILTR(OU=R&D.O=ABC Co)CERTMAP(MAP007) ACID(MULTIID)IDNFILTR(O=Verisign,Inc.L=Internet) CRITERIA(CNFAPP=&CNFAPP)CRITMAP(CRT001) ACID(ABCCUST)CNFAPP(ABCINET)CRITMAP(CRT002) ACID(ABCDFLT)CNFAPP(*)Assume a certificate is being presented by a user whose distinguished name is:CN=Bill,OU=Dept4,OU=PA,OU=Sales,O=ABC Co. The issuer’s distinguishedname contains in<strong>for</strong>mation about That we not VeriSign. How would we processthe search <strong>for</strong> this certificate?The first two entries don’t match, so we get to the section without an IDNF. Weloop through the SDNFs checking <strong>for</strong> a match. Then, we take off the CN from thecertificate distinguished name <strong>and</strong> compare the rest of the certificatedistinguished name against the SDNF. The sections starting with OU=Dept4 <strong>and</strong>OU=PA will not match. However, the section starting with OU=Sales willprovide a match <strong>and</strong> the ABCDEPT acid is assigned.Assume a user presents a certificate issued by VeriSign but not <strong>for</strong> ABC Co. Wewould get a match on CERTMAP MAP007, based on the IDNF in<strong>for</strong>mation. Thenwe would search the CRITMAP records <strong>for</strong> a matching CNFAPP. If the CNFAPPwas ABCINET, then acid ABCCUST would be assigned. All other applicationswould be assigned the default acid ABCDFLT.1–80 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!