Starting Certificate Management System
Chapter
8
Starting and Stopping CMS Instances
313
You first specified these passwords when you installed Certificate Management
System. Keep in mind that the passwords you provide for the tokens unlock a
combination of the following private keys:
•
If you have installed a Certificate Manager in the currently selected CMS
instance, the token password unlocks the private keys for the Certificate
Manager’s CA signing and SSL server certificates.
•
If you have installed a Registration Manager in the currently selected CMS
instance, the token password unlocks the private keys for the Registration
Manager’s signing and SSL server certificates.
•
If you have installed a Data Recovery Manager in the currently selected CMS
instance, the token password unlocks the private keys for the Data Recovery
Manager’s storage keys and transport and SSL server certificates.
•
If you have installed a Online Certificate Status Manager in the currently
selected CMS instance, the token password unlocks the private keys for the
Online Certificate Status Manager’s signing and SSL server certificates.
For more information about the CMS keys and certificates, see Chapter 14,
“Managing CMS Keys and Certificates.”
Note that during CMS installation, the watchdog stores all the passwords, required
by the server for starting up, in a password cache. The cache is maintained in a file
encrypted using the single sign-on password you specify during installation. When
you change any of the required passwords or provide new passwords, you must
start the server from the command-line (see “Starting From the Command Line” on
page 318) so that the watchdog can prompt you for the new passwords in order to
update the cache.
The single sign-on password eliminates the need for you to enter the various
password when starting up Certificate Management System. As a security
measure, you should consider changing the single sign-on password periodically.
For instructions, see “Password Cache” on page 326.
Also note that all passwords used in Certificate Management System are checked
by a built-in password-quality checker; for details, see “Password-Quality
Checker” on page 327.
Configuring the Server to Start Without the Single Sign-On Password
If you prefer to start up Certificate Management System by entering all the
required passwords, instead of just the single sign-on password, you can do so by
either deleting or renaming the password cache file,
pwcache.p12
(notice the
.p12
extension).
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...