Setup guide

33
Chapter 4
PIN Generator Tool
For Netscape Certificate Management System (CMS) to use the authentication
plug-in module named
UidPwdPinDirAuth your authentication directory must
contain unique PINs for each end entity to whom you intend to iss ue a certificate.
To aid you in generating P INs for end-entity entries in a directory, Certificate
Management System provides a command-line tool called the PIN Generator.This
tool allows you to generate unique PINs for entries i n an LDAP-compliant user
directory. The tool stores these PINs (as hashed values) in the same directory
against the corresponding user entries, and it copies the PINs to a text file, from
which y ou can deliver the P INs to end entities by a n appropriate, secure means.
This chapter explains how to use the PIN Generator. The chapter has the following
sections:
Locating the PIN Generator Tool (page 33)
The setpin Command (page 34)
How the Tool Works (page 38)
Locating the PIN Generator Tool
You can find the PIN Generator at this location:
<server_root>/bin/cert/tools/setpin.exe