Getting New Certificates for the Subsystems
488
Netscape Certificate Management System Installation and Setup Guide • October 2001
Also determine whether the Certificate Manager is configured to publish
certificates and CRLs to an LDAP directory and whether it uses the SSL server
certificate for SSL client authentication to the directory. If it does, you will have
to request the certificate with the appropriate extensions, and after installing
the certificate you will have to configure the publishing directory to use this
certificate.
•
You can get any number of SSL server certificates.
Decide on the CA that will sign the certificate
If you want to get a new self-signed CA certificate, you don’t have to make this
decision, because the CA itself signs it. For all other certificates, you must decide on
the CA that will sign the certificate.
If you want the certificate to be signed by an internally deployed CA, check to be
sure (for example, the policy configuration) that the CA can issue the certificate
you want request.
If you want the certificate to be signed by a public CA, find out the following:
•
Does the public CA have a public policy statement? If one is available, read it;
it may help you decide whether to request the certificate from this CA.
•
Is the public CA’s certificate already installed in the trusted CA in the trust
database of Certificate Management System? If not, do you want to install it?
•
Is the public CA a trusted CA in the trust database of Certificate Management
System? If not, do you want to trust it?
•
Can the public CA issue the certificate you want to request?
•
Does the public CA impose any restrictions on certificates it issues? For
example, if you are planning for requesting a subordinate CA certificate for a
Certificate Manager, you may want to find out whether the public CA imposes
any restrictions on the validity period, volume, or type of certificates your CA
can issue. If you are planning for requesting a signing certificate for a
Registration Manager, you may want to find out whether the public CA
imposes any restrictions on the validity period or the number of certificate
requests the Registration Manager can sign using the certificate. If you are
planning for requesting a transport certificate for a Data Recovery Manager,
you may want to find out whether the public CA imposes any restrictions on
the validity period or the number of keys the Data Recovery Manager can
archive using the certificate.
•
What information does the public CA expects you to provide with the
certificate request?
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...