Getting New Certificates for the Subsystems
490
Netscape Certificate Management System Installation and Setup Guide • October 2001
Step 4. Deploy the New Certificate
In this step, follow the instructions appropriate for the certificate you installed:
•
If you installed a new CA signing certificate for a Certificate Manager, see
“Deploying Certificate Manager’s CA Signing Certificate” on page 490.
•
If you installed a new signing certificate for a Registration Manager, see
“Deploying Registration Manager’s Signing Certificate” on page 491.
•
If you installed a new transport certificate for a Data Recovery Manager, see
“Deploying Data Recovery Manager’s Transport Certificate” on page 492.
•
If you installed a new SSL server certificate, see “Deploying a Subsystem’s SSL
Server Certificate” on page 493.
Deploying Certificate Manager’s CA Signing Certificate
If you reissued the Certificate Manager’s CA signing certificate with a new key
material, none of the certificates issued by the CA using its old key will work. For
example, if the CA has issued certificates to subordinate Certificate Managers,
Registration Managers, Data Recovery Managers, Online Certificate Status
Manager, and agents, all those certificates will become invalid—the subsystems
will fail to function and agents will fail to access the agent interfaces.
To reinstate your PKI setup, first you should get an agent certificate from the new
CA so that you can get access to the Certificate Manager’s agent interface. Once
you have access to this interface, you will be able to approve new certificate
requests from entities such as Registration Managers, Data Recovery Managers,
Online Certificate Status Managers, and agents.
To request an agent certificate from the new CA:
1.
Go to this directory: <
server_root>/cert-<instance_id>/config
2.
Open the configuration file,
CMS.cfg
, in a text editor.
3.
Locate the
agentGateway.enableAdminEnroll
parameter and change its
value from
false
to
true
. The modified parameter should look like this:
agentGateway.enableAdminEnroll=true
4.
Save your changes and close the file.
5.
Restart the server.
6.
Open a web browser window.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...