
Cloning a CA
Chapter
3
Certificate Manager
131
During the cloning process, the master Certificate Manager’s SSL server
certificate is automatically copied to the certificate database of the clone
Certificate Manager. The clone Certificate Manager uses this certificate for
SSL-client-authenticated communication with the master Certificate
Manager. Don’t be alarmed when you see the certificate in clone Certificate
Managers’ certificate databases. Also, be sure not to remove them from the
master and clone Certificate Managers’ databases.
Setting Up a Clone CA
1.
Shutdown the master CA. See “Starting, Stopping, and Restarting CMS
Instances” on page 254.
2.
Copy the Master CA’s Certificate and Key Database
Because you want the clone Certificate Manager to own the same keys and
certificates as that of the master Certificate Manager, you need to make
available the keys and certificates used by the master Certificate Manager to
each clone Certificate Manager.
❍
If the master Certificate Manager’s keys and certificates are stored in the
internal/software token, you need to copy the certificate and key database
files from the master Certificate Manager to each clone Certificate
Manager. Here’s how you do this:
I.
In the master Certificate Manager’s host machine, go to this directory:
<server_root>/alias
II.
Locate the certificate and key database files; the file names are as
follows:
cert-<instance_id>-<machine_name>-cert8.db
cert-<instance_id>-<machine_name>-key3.db
III.
In the clone Certificate Manager’s host machine, go to this directory:
<server_root>/alias
IV.
Copy the certificate and key database files from the master Certificate
Manager to the clone.
V.
Repeat steps III and IV to copy the master Certificate Manager’s
certificate and key database files to the
alias
directory of each clone
Certificate Manager.
❍
If the master Certificate Manager’s keys and certificates are stored in the
hardware token, you need to copy the keys and certificates following the
instructions provided by the hardware-token vendor.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...