Renewing Certificates for the Subsystems
Chapter
14
Managing CMS Keys and Certificates
499
To add the renewed certificate to a subsystem’s internal database:
a.
Note the instance ID and host name of the Registration Manager for which
you got the signing certificate; this information will help you to identify
the Registration Manager in a subsystem’s list of privileged users.
b.
Copy the renewed signing certificate, in its base-64 encoded format, to a
text file.
c.
Add the renewed certificate to the individual subsystem’s internal
database following the instructions in “Changing a Privileged User’s
Certificate” on page 430. Repeat this step for all subsystems that receive
requests from this Registration Manager.
2.
Ensure that the CA that signed the Registration Manager’s certificate is in the
trust database of the subsystem.
When a Registration Manager does SSL client authentication using its renewed
certificate, the subsystem, as a part of validating the certificate presented by the
Registration Manager, checks its trust database for the CA (certificate) that
signed the Registration Manager’s renewed certificate. If the subsystem does
not find the CA as a trusted CA in its trust database, it rejects the Registration
Manager.
For instructions on checking the trust database of a subsystem, see “Viewing
the Certificate Database Content” on page 502.
❍
If you don’t find the CA certificate, add it to the database as a trusted CA.
For instructions on adding a CA certificate to the trust database of a
subsystem, see “Installing a New CA Certificate in the Certificate
Database” on page 507.
❍
If you find the CA certificate, verify its trust status. If it is untrusted,
change the status to trusted. For instructions on changing the trust setting
of a CA certificate, see “Changing the Trust Settings of a CA Certificate” on
page 505.
Deploying Data Recovery Manager’s Renewed Transport Certificate
Because clients capable of generating dual key pairs use the transport certificate for
encrypting end users’ encryption private keys before sending them to the Data
Recovery Manager, you must update the appropriate enrollment or key archival
page to identify and use the renewed transport certificate. Otherwise, the Data
Recovery Manager will fail to archive users’ encryption private keys.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...