Password Cache
326
Netscape Certificate Management System Installation and Setup Guide • October 2001
Password Cache
During CMS installation, the installation program creates a password cache which
the CMS watchdog uses to store all the passwords required by the server during
start up (see “Required Start-up Information” on page 312). For example, when
you specify the cryptographic token password and the bind password for the
internal directory during installation, the watchdog adds these passwords into the
password cache; similarly, when you configure the server for LDAP publishing
from Netscape Console, the watchdog adds the corresponding password to the
cache.
The password cache is maintained in a triple-DES encrypted file named
pwcache.p12
, which is located here:
<server_root>/cert-<instance_id>/config
The file is protected using the single sign-on password you specify during
installation. In the cache, passwords are stored along with a name, a string
describing the usage of the password, which is used by Certificate Management
System to index into the cache. For example, the contents of the password cache
could look like this:
----- Password Cache -----
Internal LDAP Database : myIdbPwd
Internal Key Storage Token : myTokenPwd
Authentication : myPinAuthPwd
LDAP Publishing : myLdapPubPwd
Note that in the above example
•
The string
Internal LDAP Database
is the default value assigned to the
internaldb.ldapauth.bindPWPrompt
parameter in the CMS configuration
file; it provides a descriptive usage for the password Certificate Management
System uses to bind to the internal database.
•
The string
Internal Key Storage Token
is hardcoded and it refers to the
Netscape Software Cryptographic Service provider; you cannot change it. You
can only change the corresponding password.
Other entries may appear in the password cache. For example, if you set up
PIN-based authentication with the remove PIN option, you will see an entry for the
password Certificate Management System uses to bind to the authentication
directory to remove a PIN after a user successfully authenticates; for details, see
UidPwdPinDirAuth
plug-in module in CMS Plug-ins Guide. Similarly, if you enable
LDAP publishing with basic authentication, you will also see an entry for the
password Certificate Management System will use to bind to the publishing
directory; for details, see “Step 5. Identify the Publishing Directory” on page 656.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...