<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dr Flex &#38; Dr LiveCycle &#187; LiveCycle Rights Management ES</title>
	<atom:link href="http://www.drflex.eu/category/livecycle/livecycle-rights-management-es/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.drflex.eu</link>
	<description>Latest news from the cabinet</description>
	<lastBuildDate>Fri, 12 Mar 2010 22:27:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Using the Belgian eid card for accessing a LiveCycle Rights Management protected document</title>
		<link>http://www.drflex.eu/2009/01/using-the-belgian-eid-card-for-accessing-a-livecycle-rights-management-protected-document/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=using-the-belgian-eid-card-for-accessing-a-livecycle-rights-management-protected-document</link>
		<comments>http://www.drflex.eu/2009/01/using-the-belgian-eid-card-for-accessing-a-livecycle-rights-management-protected-document/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 15:23:18 +0000</pubDate>
		<dc:creator>Peter Schellemans</dc:creator>
				<category><![CDATA[LiveCycle Digital Signatures ES]]></category>
		<category><![CDATA[LiveCycle Rights Management ES]]></category>

		<guid isPermaLink="false">http://www.drflex.eu/?p=97</guid>
		<description><![CDATA[Disease: Typically LiveCycle Rights Management (a.k.a. Policy) protected documents use a userid/password mechanism for authenticating towards the policy server, and consequently open the protected document. A more secure way of authentication can be obtained by using client certificates. A real strong way of authentication can be accomplished when the authentication certificate resides on a smartcard, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Disease:<br />
</strong>Typically LiveCycle Rights Management (a.k.a. Policy) protected documents use a userid/password mechanism for authenticating towards the policy server, and consequently open the protected document. A more secure way of authentication can be obtained by using client certificates. A real strong way of authentication can be accomplished when the authentication certificate resides on a smartcard, protected by a PIN code. The authentication certificate on the Belgian eid card is such an example. How can that be used to authenticate towards a Policy protected document?</p>
<p><strong>Prescription:</strong><br />
To achieve this follow these steps:<br />
1) First of all the authentication certificate must be known/registered/uploaded to the LiveCycle server. Open the adminui &#8211;&gt; Settings &#8211;&gt; Trust Store Management &#8211;&gt; Certificates.<br />
When importing the .cer file, specify that you want to trust the certificate for &#8220;Certificate Authentication&#8221;, and provide an alias.</p>
<p>2) Next this certificate must be mapped to an existing user in LiveCycle.<br />
Open the adminui &#8211;&gt; Settings &#8211;&gt; User Management &#8211;&gt; Configuration &#8211;&gt; Certificate mapping.<br />
The mapping between a certificate and a user is done for a defined alias, and is accomplished by mapping a certificate attribute (Mail, CN, DN,&#8230; ) to a user property (Full Name, Given Name, Mail, login ID, &#8230;).</p>
<p>In the case of the Belgian eid card the CN on the authentication certificate contains also the word &#8220;Authentication&#8221;. In my case my CN = Peter Schellemans (Authentication). So in order to get a working certificate mapping towards an existing user, make sure you have a user with a similar Full Name. In my case I have a user (adminui &#8211;&gt; Settings &#8211;&gt; User Management &#8211;&gt; Users and Groups) with First Name = Peter, Last Name = Schellemans (Authentication).</p>
<p>3) Next add this user as part of your Policy. When opening the policy protected document you will now get the choice between userid/password authentication and client certificate authentication.</p>
<p><strong>Tip to stay healthy:</strong><br />
If you want a higher level of security when authenticating towards a policy protected document, Adobe LiveCycle allows you to map certificates towards users, used in a policy definition.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.drflex.eu/2009/01/using-the-belgian-eid-card-for-accessing-a-livecycle-rights-management-protected-document/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>



