Keys and Certificates for the Main Subsystems
444
Netscape Certificate Management System Installation and Setup Guide • October 2001
2.
Stop Certificate Management System.
3.
Open a command window.
4.
Go to this directory:
<server_root>/cert-<instance_id>/config
5.
Enter the command below, replacing
<certname>
with the name of the remote
administration SSL server certificate. You may use the
-h <tokenname>
argument to specify whether the certificate database is on a particular
hardware or software token.
certutil -L -n “<certname>”
For example, your command might look like this:
certutil -L -n “Remote Admin Server-Cert cert-firefly”
You should see detailed information about the remote administration SSL
server certificate.
6.
Locate the “Subject Public Key Info:” section and then the Modulus section. For
example:
RSA Public Key:
Modulus:
00:f6:9e:71:37:62:af:7c:46:af:cb:bf:1e:d8:1a:
64:0b:5e:71:e2:d8:ec:88:18:6d:eb:32:65:6f:f2:
18:4b:ef:b3:70:ae:61:de:6f:21:d5:4e:0e:7b:9b:
b7:42:98:94:1c:d7:46:42:53:39:db:10:07:6c:b8:
75:7e:94:18:b5
7.
Note the second and third byte (
f69e
in the above example) in the modulus;
this is the short key ID for the certificate.
8.
Delete the certificate you want to renew.
9.
Run the
certutil
command again to regenerate the certificate for the correct
key and to add the resulting certificate to the database. Be sure to use the same
name for the certificate and to add the required certificate extensions, such as
the Key Usage extension. A sample command syntax is below:
certutil -S -k <shortkeyID> -y rsa|dsa -n "<certname>"
-s "<subject>" -t "<trustargs>"
-x -m <serial-number>
-v <valid-months> -d <certdir> -1)
For example, your command might look like this:
certutil -S -k f69e -y rsa -n "Remote Admin Server-Cert
cert-firefly" -s "cn=SSLserver cert-firefly" -t "u,u,u" -x -m 3
-v 12 -d . -1
10.
Restart Certificate Management System.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...