ibm-information-center/dist/eclipse/plugins/i5OS.ic.rzahu_5.4.0.1/rzahumanageuserexpire.htm

102 lines
7.5 KiB
HTML

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-us" xml:lang="en-us">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta name="security" content="public" />
<meta name="Robots" content="index,follow" />
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<meta name="DC.Type" content="task" />
<meta name="DC.Title" content="Manage user certificates by expiration" />
<meta name="abstract" content="Digital Certificate Manager (DCM) provides certificate expiration management support to allow administrators to check the expiration dates of user certificates on the local iSeries system. DCM user certificate expiration management support can be used in conjunction with Enterprise Identity Mapping (EIM) so that administrators can use DCM to check user certificate expiration at the enterprise level." />
<meta name="description" content="Digital Certificate Manager (DCM) provides certificate expiration management support to allow administrators to check the expiration dates of user certificates on the local iSeries system. DCM user certificate expiration management support can be used in conjunction with Enterprise Identity Mapping (EIM) so that administrators can use DCM to check user certificate expiration at the enterprise level." />
<meta name="DC.Relation" scheme="URI" content="rzahurzahu404selectingusercatasks.htm" />
<meta name="DC.Relation" scheme="URI" content="rzahuandeim.htm" />
<meta name="DC.Relation" scheme="URI" content="../rzalv/rzalvmst.htm" />
<meta name="copyright" content="(C) Copyright IBM Corporation 2000, 2006" />
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2000, 2006" />
<meta name="DC.Format" content="XHTML" />
<meta name="DC.Identifier" content="rzahu_manage_user_expire" />
<meta name="DC.Language" content="en-us" />
<!-- All rights reserved. Licensed Materials Property of IBM -->
<!-- US Government Users Restricted Rights -->
<!-- Use, duplication or disclosure restricted by -->
<!-- GSA ADP Schedule Contract with IBM Corp. -->
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
<link rel="stylesheet" type="text/css" href="./ic.css" />
<title>Manage user certificates by expiration</title>
</head>
<body id="rzahu_manage_user_expire"><a name="rzahu_manage_user_expire"><!-- --></a>
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
<h1 class="topictitle1">Manage user certificates by expiration</h1>
<div><p>Digital Certificate Manager (DCM) provides certificate expiration
management support to allow administrators to check the expiration dates of
user certificates on the local <span class="keyword">iSeries™</span> system.
DCM user certificate expiration management support can be used in conjunction
with Enterprise Identity Mapping (EIM) so that administrators can use DCM
to check user certificate expiration at the enterprise level.</p>
<div class="section"> <p></p>
<p>To take advantage of expiration management support for
user certificates at the enterprise level, EIM must be configured in the enterprise
and EIM must contain the appropriate mapping information for user certificates.
To check the expiration of user certificates other than those associated with
your own user profile, you must have *ALLOBJ and *SECADM special authorities. </p>
<p>Using
DCM to view certificates based on their expiration allows you to determine
quickly and easily which certificates are close to expiring so that certificates
can be renewed in a timely fashion. </p>
<p>To view and manage user certificates
based on their expiration dates, follow these steps:</p>
</div>
<ol><li class="stepexpand"><span><a href="rzahurzahu66adcmstart.htm#rzahu66a-dcm_start">Start
DCM</a>.</span> <div class="note"><span class="notetitle">Note:</span> If you have questions about how to complete a
specific form while using DCM, select the question mark (<span class="uicontrol">?</span>)
at the top of the page to access the online help. </div>
</li>
<li class="stepexpand"><span>In the navigation frame, select <span class="uicontrol">Manage User Certificates</span> to
display a list of tasks. </span> <div class="note"><span class="notetitle">Note:</span> If you are currently working with
a certificate store, select <span class="uicontrol">Manage Certificates</span> to
display a list of tasks, then select <span class="uicontrol">Check expiration</span>,
and select <span class="uicontrol">User</span>.</div>
</li>
<li class="stepexpand"><span>If your user profile has *ALLOBJ and *SECADM special authorities,
you can select a method for choosing which user certificates to view and manage
based on their expiration dates. (If your user profile does not have these
special authorities, DCM prompts you to specify the expiration date range
as described in the next step.) You can select one of the following: </span> <ul><li><span class="uicontrol">User profile</span> to view and manage user certificates
that are assigned to a specific <span class="keyword">i5/OS™</span> user
profile. Specify a <span class="uicontrol">User profile name</span> and click <span class="uicontrol">Continue</span>.
<div class="note"><span class="notetitle">Note:</span> You can specify a user profile other than your own user profile only
if you have *ALLOBJ and *SECADM special authorities.</div>
</li>
<li><span class="uicontrol">All user certificates</span> to view and to manage user
certificates for all user identities. </li>
</ul>
</li>
<li class="stepexpand"><span>In the <span class="uicontrol">Expiration date range in days (1-365)</span> field,
enter the number of days for which to view user certificates based on their
expiration date and click <span class="uicontrol">Continue</span>. DCM displays all
user certificates for the specified user profile that expire between today's
date and the date that matches the number of specified days. DCM also displays
all user certificates that have expiration dates before today's date. </span></li>
<li class="stepexpand"><span>Select a user certificate to manage. You can choose to view certificate
information details or remove the certificate from the associated user identity. </span></li>
<li class="stepexpand"><span>When you finish working with certificates from the list, click <span class="uicontrol">Cancel</span> to
exit the task.</span></li>
</ol>
<div class="section"></div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="rzahurzahu404selectingusercatasks.htm" title="You can use Digital Certificate Manager (DCM) to obtain certificates with SSL or associate existing certificates with their iSeries user profiles.">Manage user certificates</a></div>
</div>
<div class="reltasks"><strong>Related tasks</strong><br />
<div><a href="rzahuandeim.htm" title="Using Enterprise Identity Mapping (EIM) and Digital Certificate Mangers (DCM) together allows you to apply a certificate as the source of an EIM mapping lookup operation to map from the certificate to a target user identity associated with the same EIM identifier.">Digital certificates and Enterprise Identity Mapping (EIM)</a></div>
</div>
<div class="relinfo"><strong>Related information</strong><br />
<div><a href="../rzalv/rzalvmst.htm">EIM Information Center Overview</a></div>
</div>
</div>
</body>
</html>