
Tokens for Storing CMS Keys and Certificates
Chapter
7
Administrative Basics
319
Managing Tokens Used by the Subsystems
There are two main tasks involved in managing the tokens used by Certificate
Management System:
•
Viewing Tokens
•
Changing a Token’s Password
Viewing Tokens
To view a list of the tokens currently installed for a CMS instance:
1.
Log in to the CMS window (see “Logging Into the CMS Console” on page 247).
2.
Select the Configuration tab, and then in the right pane, select the Encryption
tab.
3.
In the Map To section, check the Token drop-down list.
It shows the names (as specified when the tokens were installed) of external
tokens installed for the currently selected CMS instance. For information on
installing external tokens, see “External Token” on page 316.
Changing a Token’s Password
The token, internal or external, that stores the key pairs and certificates for the
subsystems is protected (encrypted) by a password. To decrypt the key pairs or to
gain access to them, you must enter that password. The first time you specified this
password is when you used the token the first time, most likely during CMS
installation.
It is good security practice to periodically change the password that protects your
server’s keys and certificates; changing the password periodically minimizes the
risk of someone finding out the password. To change a token’s password, use the
certutil
command-line utility, the documentation for which can be found at this
site:
http://www.mozilla.org/projects/security/pki/nss/tools/
Note that the single sign-on password cache stores the passwords for tokens in
order to start the server using a single password; for details, see “Starting,
Stopping, and Restarting CMS Instances” on page 254. Whenever you change the
password, the cache is updated with the new password.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...