CEP Enrollment Using the Script
810
Netscape Certificate Management System Installation and Setup Guide • October 2001
Note that Certificate Management System by default supports issuance of
certificates to routers and VPN clients using the CEP-based enrollment. However,
publishing of these certificates to an LDAP-compliant directory is not turned on by
default because routers and VPN clients need to have access to an LDAP directory
in order to fully support various functions, such as certificate and CRL retrieval.
This section explains how to set up a Certificate Manager to issue certificates to
routers and CEP-compliant Virtual Private Network (VPN) clients. The section also
describes how to configure the Certificate Manager to publish these certificates and
certificate revocation lists (CRLs) to an LDAP-compliant directory.
You may configure the Certificate Manager to publish to any LDAP-compliant
directory, but if you do not have one available, you can use the one supplied with
Certificate Management System. Certificate Management System comes with
Netscape Directory Server, which is an LDAP-compliant directory. When you
install Certificate Management System, two instances of Netscape Directory Server
are automatically created in the same server group in which Certificate
Management System is installed—one of the Directory Server instances is
identified as the configuration directory and the other internal database. For
publishing certificates and CRLs you may use the configuration directory, but not
the internal database. The internal database is configured for exclusive use by
Certificate Management System; see , “Setting Up Internal Database.”
There are two ways to set up CEP enrollment:
•
CEP Enrollment Using the Script
•
Setting up CEP Enrollment Manually
The sections that follow explain both ways of CEP enrollment in detail. The
recommended is to use the interactive script.
CEP Enrollment Using the Script
Certificate Management System provides a menu-driven, interactive script to
automate the CEP enrollment process. To invoke the script:
1.
Go to the Certificate Manager’s host system.
2.
Open a command-line window.
3.
Go to this directory:
<server_root>
4.
Enter either the following, depending on your system, at the prompt:
% install/perl bin/cert/tools/cepconfig.pl
on UNIX
% install\perl bin\cert\tools\cepconfig.pl
on Windows NT
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...