Configuring the Server’s Security Preferences
478
Netscape Certificate Management System Installation and Setup Guide • October 2001
•
If you installed (or imported) a certificate chain, the wizard adds (to the local
trust database) the first certificate in the chain as a trusted CA certificate and
any subsequent certificates as untrusted CA certificates. For more information
on how the wizard installs a certificate chain, see “Using the Wizard to Install a
Certificate or Certificate Chain” on page 471.
Step 6. Verify the Certificate Status
This step is applicable only if you installed a certificate chain.
After you install a certificate chain in the trust database of a CMS instance, check
the trust status of each certificate that got installed, and make sure that the correct
CA certificates are trusted. For instructions, see “Changing the Trust Settings of a
CA Certificate” on page 505.
Configuring the Server’s Security Preferences
Configuring a CMS manager’s security preferences involves identifying the
following:
•
The SSL server certificates a server must use for authenticating to the end
entity, agent, and administration interfaces. For details, see “Configuring the
Server to Use Separate SSL Server Certificates” on page 478.
•
The SSL client certificate a Certificate Manager must use for authenticating to
the publishing directory (if the Certificate Manager is configured to publish
certificates and CRLs to the directory). For details, see “Getting an SSL Client
Certificate for a Subsystem” on page 480.
•
The version of SSL that an instance of Certificate Management System must
use during SSL communication. The latest version is SSL version 3, but many
older clients use SSL version 2. Because client authentication is required for
performing privileged operations, you must enable SSL version 3 ciphers
supported by Certificate Management System. For details, see “Setting Up
Cipher Preferences for SSL Communications” on page 482.
Configuring the Server to Use Separate SSL
Server Certificates
You can configure a CMS instance to use separate SSL server certificates for
authenticating to Netscape Console, the Agent Services interface, and the end
entity services interface.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...