How To Create a Complete Wallet: Process Overview
8-8
Oracle Database Advanced Security Administrator's Guide
How To Create a Complete Wallet: Process Overview
Wallets provide a necessary repository in which you can securely store your user
certificates and the
trust point
s
you need to validate the certificates of your peers.
The following steps provide an overview of the complete wallet creation process:
1.
Use Oracle Wallet Manager to create a new wallet:
■
See
"Required Guidelines for Creating Wallet Passwords"
on page 8-9 for
information about creating a wallet password
■
See
"Creating a New Wallet"
on page 8-10 for information about creating
standard wallets (store credentials on your file system) and hardware
security module wallets.
2.
Generate a certificate request. Note that when you create a new wallet with
Oracle Wallet Manager, the tool automatically prompts you to create a
certificate request. See
"Adding a Certificate Request"
on page 8-21 for
information about creating a certificate request.
3.
Send the certificate request to the CA you want to use. You can copy and paste
the certificate request text into an e-mail message, or you can export the
certificate request to a file. See
"Exporting a User Certificate Request"
on
page 8-25. Note that the certificate request becomes part of your wallet and
must remain there until you remove its associated certificate.
4.
When the CA sends your signed user certificate and its associated
trusted
certificate
, then you can import these certificates in the following order. (Note
that user certificates and trusted certificates in the PKCS #7 format can be
imported at the same time.)
■
First import the CA's trusted certificate into your wallet. See
"Importing a
Trusted Certificate"
on page 8-25 Note that this step may be optional if the
new user certificate has been issued by one of the CAs whose trusted
certificate is already present in Oracle Wallet Manager by default.
■
After you have successfully imported the trusted certificate, then import the
user certificate that the CA sent to you into your wallet. See
"Importing the
User Certificate into the Wallet"
on page 8-22
5.
(Optional) Set the auto login feature for your wallet. See
"Using Auto Login"
on
page 8-19.
Typically, this feature, which enables PKI-based access to services without a
password, is required for most wallets. It is required for database server and
Summary of Contents for Database Advanced Security 10g Release 1
Page 17: ...xvii ...
Page 20: ...xx ...
Page 24: ...xxiv ...
Page 42: ...xlii ...
Page 44: ......
Page 102: ......
Page 124: ......
Page 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Page 284: ......
Page 384: ......
Page 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Page 518: ...Index 10 ...