![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 137](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697137.webp)
Installing a Registration Manager
Chapter
4
Registration Manager
137
If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, check this
document:
http://www.itl.nist.gov/div897/pubs/fip186.htm
.
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
(Certificate Manager CA signing keys up to 2048 bits in length are not subject to
export restrictions.)
Many people no longer consider an RSA key of length less than 1024 bits to be
cryptographically strong. Export and other regulations permitting, it may be a
good rule of thumb to start with 1024 bits and consider increasing the length to
4096 bits for certificates that provide access to highly sensitive data or services.
However, the question of key length has no simple answers. Every organization
must make its own decision based on its own security requirements. For more
information on key length and encryption strength, see Appendix D of Managing
Servers with Netscape Console.
Tokens
You choose either the
internal
token (if you plan to use the internal/software
token) or an external token to store the signing certificate and key pair and the SSL
signing certificate and key pair.
If you are using an external token, you will need to install it before you run the
Installation Wizard. In the wizard, you can select from a list of already installed
and available tokens. For example,
SmartCard
. For installation instructions, see
“External Token” on page 314.
Installing a Registration Manager
To install a standalone Registration Manager:
1.
Log into Netscape Console as the administrator.
2.
Select the CMS instance and then either click Open, or double click this
instance.
The Installation Wizard launches.
3.
Installation Wizard Introduction.
Click Next to continue.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...