Keys and Certificates for the Main Subsystems
Chapter
14
Managing CMS Keys and Certificates
449
Online Certificate Status Manager’s Key Pairs
and Certificates
The Online Certificate Status Manager uses the following certificates:
•
OCSP Signing Key Pair and Certificate
•
SSL Server Key Pair and Certificate
•
Remote Administration Server Certificate
OCSP Signing Key Pair and Certificate
Every Online Certificate Status Manager you have installed has a certificate,
identified as the Online Certificate Status Manager signing certificate, whose public
key corresponds to the private key the Online Certificate Status Manager uses to
sign OCSP responses before sending them to OCSP-compliant clients. The Online
Certificate Status Manager’s signature provides persistent proof to an
OCSP-compliant client that the Online Certificate Status Manager has processed
the request. The first time you generated this certificate is when you installed the
Online Certificate Status Manager. The default nickname for the certificate is
ocspSigningCert cert-<instance_id>
, where
<instance_id>
identifies the
CMS instance in which the Online Certificate Status Manager is installed.
The Online Certificate Status Manager’s signing certificate was issued by the CA to
which you submitted the certificate signing request. You might have submitted the
request to an internally deployed CA or a public CA. To find out the issuer name,
follow the instructions in “Viewing the Certificate Database Content” on page 502.
SSL Server Key Pair and Certificate
Every Online Certificate Status Manager you have installed has at least one SSL
server certificate. The first time you generated this certificate is when you installed
the Online Certificate Status Manager. The default nickname for the certificate is
Server-Cert cert-<instance_id>
, where
<instance_id>
identifies the CMS
instance in which the Online Certificate Status Manager is installed.
The Online Certificate Status Manager’s SSL server certificate was issued by the CA
to which you submitted the certificate signing request. You might have submitted
the request to an internally deployed CA or a public CA. To find out the issuer
name, follow the instructions in “Viewing the Certificate Database Content” on
page 502.
The Online Certificate Status Manager uses its SSL server certificate to do SSL
server-side authentication to the Online Certificate Status Manager Agent Services
interface.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...