![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 174](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697174.webp)
Installing an Online Certificate Status Manager
174
Netscape Certificate Management System Administrator’s Guide • June 2003
If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, check this
document:
http://www.itl.nist.gov/div897/pubs/fip186.htm
.
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
Many people no longer consider an RSA key of length less than 1024 bits to be
cryptographically strong. Export and other regulations permitting, it may be a
good rule of thumb to start with 1024 bits and consider increasing the length to
4096 bits for certificates that provide access to highly sensitive data or services.
(CMS signing keys up to 2048 bits in length are not subject to export restrictions.)
However, the question of key length has no simple answers. Every organization
must make its own decision based on its own security requirements. For more
information on key length and encryption strength, see Appendix D of Managing
Servers with Netscape Console.
Installing an Online Certificate Status Manager
To install a standalone Online Certificate Status Manager:
1.
Log into Netscape Console as the administrator.
2.
Select the CMS instance and then either click Open, or double click this
instance.
The Installation Wizard launches.
3.
Installation Wizard Introduction.
Click Next to continue.
4.
Logon Token.
Enter either
internal
(if you plan to use the internal/software
token) or the name of an external token to store the Certificate Manager signing
certificate and key pair. If you have not previously initialized the token’s
password, you must do so in this screen. See “Tokens,” on page 173 for more
information.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...