
228
OES 2 SP2: Planning and Implementation Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
22.1.3 Multiple Trees Sharing a Common Root
The Organizational CA can be configured to act as a sub-CA. This lets multiple trees share a
common root certificate. The root certificate can be stored in a physically protected tree. It can also
integrate with a third-party PKI. For more information, see “
Subordinate Certificate Authority
” in
the
Novell Certificate Server 3.3.2 Administration Guide
.
22.2 Setting Up Certificate Management
Use the information in the following sections to help you set up certificate management as you
install OES 2.
Section 22.2.1, “Setting Up Automatic Certificate Maintenance,” on page 228
Section 22.2.2, “Eliminating Browser Certificate Errors,” on page 228
22.2.1 Setting Up Automatic Certificate Maintenance
To set up your server so that HTTPS services use eDirectory certificates, you must specify the
Use
eDirectory Certificates for HTTP Services
option while installing or upgrading eDirectory.
This installs eDirectory keys and certificates on the server, but it does not configure the server to
automatically replace the certificates when they expire. Automatic maintenance requires that Server
Self-Provisioning be enabled as follows:
1
On the server you are configuring, in iManager > Roles and Tasks, click the
Novell Certificate
Access > Configure Certificate Authority
option.
2
Click
Enable server self-provisioning
.
This causes automatic certificate replacement for the conditions described in
“PKI Health
Check” on page 227
.
IMPORTANT:
If you enable Server Self-Provisioning in an OES 2 tree and you have created a
CRL configuration object but not yet configured any CRL distribution points, the PKI Health
Check might replace the default certificates every time it runs.
To avoid this, you can either
Finish configuring the CA's CRL capability by creating one or more CRL Distribution Points
by using iManager's
Configure Certificate Authority
task.
or
Delete any CRL Configuration objects, for example CN=One - Configuration.CN=CRL
Container.CN=Security.
3
If you also want the CA certificate to be replaced if it changes or expires, click the
Health
Check - Force default certificate creation/update on CA change
option.
22.2.2 Eliminating Browser Certificate Errors
Because the Internet Explorer and Mozilla Firefox* browsers don’t trust eDirectory certificate
authorities by default, attempts to establish a secure connection with OES 2 servers often generate
certificate errors or warnings.
These are eliminated by importing the eDirectory tree CA’s self-signed certificate into the browsers.
Summary of Contents for OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Page 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...