Using the Default Demo
150
Netscape Certificate Management System Installation and Setup Guide • October 2001
5.
Click OK, and provide your key database password if requested.
After the key is generated, your browser submits the certificate request to the
Certificate Manager. The Certificate Manager verifies the request against all
applicable policies (including the RSA key length policy for client certificates
you configured earlier). The response from the server will be a Request
Rejected page explaining that the request violated the
RSAKeyRule
policy.
6.
Use your browser’s Back button to return to the Directory-based enrollment
form. If the identity information is no longer present, enter the User ID and
Password again.
7.
Change the Key Length setting to 1024 (High Grade), and click Submit.
A dialog box asks whether to generate a private key.
8.
Click OK, and provide your key database password if requested.
The new certificate is issued immediately and installed in your browser.
Next, you will configure Certificate Management System to publish (in the
directory) the certificate you just issued.
Publish Certificates to an LDAP Directory
In any PKI there are things that you need to publish to make them available to
entities. Certificate revocation lists (CRLs), for example, can be made available at a
well known URL so that clients and servers can check them as needed instead of
fetching and storing the list every time it is updated. In a PKI where people need to
exchange encrypted files or email, you do not want each person to have to store
everyone else’s public key; instead, you can publish certificates to a directory or
database and allow users to look up public keys as needed.
In this example, you will configure a Certificate Manager to publish new
certificates to an existing directory (the configuration directory that Netscape
Console uses).
To publish certificates to a directory, you must configure information about the
destination directory, configure the rules for publishing to it, then update the
directory. Updating the directory publishes certificates that were issued before
publishing was enabled; certificates issued later will be published automatically as
they are issued.
Before you change the configuration you should understand the basics of the
flexible components that make up the Certificate Management System publishing
system: mappers, publishers, and rules.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...