Cloning the Online Certificate Status Manager
Chapter
16
Configuring CMS for High Availability
687
1.
From the Object menu in the Netscape Console, choose Create Instance Of,
then choose Netscape Certificate Management System. Alternatively, you can
right-click the Server Group node and choose Create Instance Of > Netscape
Certificate Management System. The admin console asks you to provide a
name for the new instance; enter the name of the new Online Certificate Status
Manager instance in the dialog provided.
2.
The Installation Wizard displays a dialog asking you to specify whether this
new instance is a clone. Answer Yes and click Next.
3.
The Installation Wizard asks you to copy the key and certificates from the
master OCSP Responder to the clone if you have not already done so.
4.
Copy the master OCSP Responder’s Certificate and Key Database.
Because you want the cloned Online Certificate Status Manager to own the
same keys and certificates as that of the master Online Certificate Status
Manager, you need to make the keys and certificates used by the master
available to the Online Certificate Status Manager clone.
❍
If the master Online Certificate Status Manager’s keys and certificates are
stored in the internal/software token, you need to copy the certificate and
key database files from the master to the Online Certificate Status Manager
clone. Here’s how you do this:
I.
In the master Online Certificate Status Manager’s host machine, go to
this directory:
<server_root>/alias
II.
Locate the certificate and key database files for the Online Certificate
Status Manager; the file names are as follows:
cert-<ocsp_instance_id>-<machine_name>-cert8.db
cert-<ocsp_instance_id>-<machine_name>-key3.db
III.
On the host machine of the clone, go to this directory:
<server_root>/alias
IV.
Copy the certificate and key database files from the master Online
Certificate Status Manager to the clone.
❍
If the master Online Certificate Status Manager’s keys and certificates are
stored in the hardware token, you need to copy the keys and certificates
following the instructions provided by the hardware-token vendor.
5.
Open the Server Group item, select the cloned OCSP Responder, and click
Open again to resume configuration where you left off in the installation
wizard.
6.
Designate the password for the internal token in the Logon Token dialog.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...