Designing Your Novell eDirectory Network
83
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
The root administrator can also delegate the authority to use the Organizational CA by assigning the
following rights to subcontainer administrators. Subcontainer administrators require the following
rights to install Novell eDirectory with SSL security:
• Read right to the NDSPKI:Private Key attribute on the Organizational CA’s object, located in
the Security container.
• Supervisor right to the W0 object located in the Security container, inside the KAP object.
These rights are assigned to a group or a role, where all the administrative users are defined. For a
complete list of required rights to perform specific tasks associated with Novell Certificate Server,
refer to the
Novell Certificate Server (http://www.novell.com/documentation/beta/crt30/index.html)
online documentation.
2.7.2 Ensuring Secure eDirectory Operations on Linux, Solaris,
AIX, and HP-UX Systems
eDirectory includes Public Key Cryptography Services (PKCS), which contains the Novell
Certificate Server that provides Public Key Infrastructure (PKI) services, Novell International
Cryptographic Infrastructure (NICI), and SAS*-SSL server.
The following sections provide information about performing secure eDirectory operations:
•
“Verifying Whether NICI Is Installed and Initialized on the Server” on page 83
•
“Initializing the NICI Module on the Server” on page 84
•
“Starting the Certificate Server (PKI Services)” on page 85
•
“Stopping the Certificate Server (PKI Services)” on page 85
•
“Creating an Organizational Certificate Authority Object” on page 85
•
“Creating a Server Certificate Object” on page 85
•
“Exporting an Organizational CA's Self-Signed Certificate” on page 85
For information about using external certificate authority, refer to the
Novell Certificate Server
Administration Guide
(http://www.novell.com/documentation/beta/crt30/index.html)
.
Verifying Whether NICI Is Installed and Initialized on the Server
Verify the following conditions, which indicate that the NICI module has been properly installed and
initialized:
• The file
/etc/nici.cfg
exists
• The directory
/var/novell/nici
exists
• The file
/var/novell/nici/primenici
exists
Creating Server Certificate objects
Supervisor right on the server’s container
Read right to the NDSPKI:Private Key attribute
on the Organizational CA’s object
Novell Certificate Server Task
Rights Required
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...