Online Certificate Status Manager Deployment Considerations
Chapter
5
OCSP Responder
175
Password Storage
Each subsystem stores passwords for its internal database, and for the tokens
containing its keys and certificates. See “System Passwords,” on page 252 for
information on how these passwords are stored.
Tokens
You choose either the
internal
token (if you plan to use the internal/software
token) or an external token to store the signing certificate and key pair and the SSL
signing certificate and key pair.
If you are using an external token, you will need to install it before you run the
Installation Wizard. In the wizard, you can select from a list of already installed
and available tokens. For example,
HSM
. For installation instructions, see “External
Token” on page 316.
Internal Database
Each subsystem uses an internal database to store information (such as certificates
and certificate requests) used by the subsystem you will be installing in this CMS
instance. By default, a separate internal database is created for each subsystem you
configure. You can choose to use the same internal database for more than one
subsystem by specifying this when running the installation wizard to configure
that subsystem. You should carefully consider whether you want to store this
information in a separate internal database for each subsystem or use one internal
database for all subsystems installed on the host.
It’s recommended that you do not use this Directory Server instance for any other
purposes; the directory schema will be configured for storing CMS data.
Signing Key Type and Length
If you wish, you can import the signing key and certificate used in a previous
version of CMS installation rather than generating a new signing key pair. For
information on how to do this, check the migration information in Step 6 of the
section “Upgrading” in Chapter 2 of the Command-Line Tools Guide.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...