Managing the Certificate Database
Chapter
7
Administrative Basics
309
8.
When you receive the certificate from the CA, install it following the
instructions in “Using the Wizard to Install a Certificate or Certificate Chain”
on page 309.
Step 8. Check the Certificate Request Status
The wizard now informs you of the status of the request.
•
If you requested a self-signed CA certificate, the wizard automatically submits
the CSR to the CA. If the CSR includes all the required information, the CA
signs the certificate and returns it to the wizard, which then installs it in the
appropriate token.
•
If you requested any other certificate, you must get the certificate from the CA
and install it using the process outlined in “Using the Wizard to Install a
Certificate or Certificate Chain” on page 309.
Using the Wizard to Install a Certificate or Certificate Chain
The Certificate Setup Wizard allows you to install or import the following
certificates into either an internal or external token used by the currently selected
CMS instance:
•
Any of the certificates used by a Certificate Manager, Registration Manager,
Data Recovery Manager, and Online Certificate Status Manager
•
Any other trusted CA certificates (certificates of CAs that you want to trust)
•
Certificate chains
A certificate chain typically includes a collection of certificates: the subject
certificate, the trusted root CA certificate, and any intermediate CA certificates
needed to link the subject certificate to the trusted root. However, the
certificate chain the wizard allows you to import must include only CA
certificates; none of the certificates can be a user certificate.
In a certificate chain, each certificate in the chain is encoded as a separate
DER-encoded object. When the wizard imports a certificate chain, it imports
these objects one after the other, all the way up the chain to the last certificate,
which may or may not be the root CA certificate. If any of the certificates in the
chain already exist in the local certificate database, the wizard replaces them by
the ones included in the chain. If the chain includes intermediate CA
certificates, the wizard adds them to the certificate database as untrusted CA
certificates.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...