Cloning the Certificate Manager
Chapter
16
Configuring CMS for High Availability
679
b.
Stop the master CA server by issuing the following command in that
directory:
./stop-cert
c.
Go to the master CA’s server config directory:
cd <serverRoot>/cert-<masterID>/config
d.
Edit the CMS.cfg file by adding the following line:
ca.listenToCloneModifications=true
e.
Close and save the CMS.cfg file.
f.
Go to the master CA directory at the command line:
cd <serverRoot>/cert-<masterID>
g.
Restart the master CA server by issuing the following command in that
directory:
./start-cert
Once the configuration for the cloned CA instance is done, the cloned CA instance
will be available. The administrator should be able to see all the requests and
certificates from either this cloned CA or the master CA. Additionally, for the
purpose of high availability, it is strongly encouraged that CRL publishing is
enabled in this cloned CA, presuming that CRL publishing has been enabled in the
master CA.
Also, it should be understood that any configurations made to a master CA will
also need to be setup in each cloned CA. The only two exceptions to this rule are
the Users and Groups and the Access Control Lists, both of which are provided
through the CMS console.
Testing the CA Cloned-Master Connection
Follow these steps to test whether your cloned-master CA setup is complete and
functional.
1.
Request a certificate from the cloned CA.
2.
Approve the request.
Skip this step if you requested the certificate using any of the automated
enrollment methods. Complete this step if you used the agent-approved
enrollment form for requesting the certificate; the request you submitted is
waiting in the agent queue for approval by an agent.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...