
Configuring the Certificate Manager
110
Red Hat Certificate System Administrator’s Guide • September 2005
Validity periods of certificates during enrollment is determined by the
ValidityConstraints
plug-in module, “ValidityConstraints,” on page 487.
Similarly, validity periods of certificates during renewal is determined by the
RenewalValidityConstraints
plug-in module, see “RenewalValidityConstraints,”
on page 481.
Certificate Serial Number.
Specifies the serial number range for certificates issued by
this Certificate Manager. The server assigns the serial number you enter in the “Next
serial number” to the next certificate it issues and the number you enter in the “Ending
serial number” to the last certificate it issues.
The serial number range enables you to deploy multiple CAs, balancing the number of
certificates each CA issues. Note that the combination of an issuer name and a serial
number uniquely identifies a certificate. To ensure that two distinct certificates issued
by the same authority doesn’t contain the same serial number, make sure the serial
number range does not overlap among cloned CAs.
Also note that when a CA exhausts all its serial numbers, you can revive it by changing
the values in the “Next serial number” and “Ending serial number” fields, followed by
restarting the Certificate Manager.
Default Signing Algorithm section.
Specifies the signing algorithm the Certificate
Manager should use for signing certificates. The choices are “MD2 with RSA”, “MD5
with RSA”, and “SHA1 with RSA”, if the CA’s signing key type is RSA and “SHA1
with DSA”, if the CA’s signing key type is DSA.
Note that the signing algorithm specified in the Certificate Manager’s policy
configuration or certificate profile configuration overrides the algorithm you select
here.
4.
To save your changes, click Save.
Setting Up Authentication
The first step in configuring enrollment is setting up authentication. You can set up more
than one type of authentication. Each type you set up must be associated with a particular
form in the interface. If you are using the certificate profile feature for enrollments, the
forms are dynamically generated with the content being determined by the inputs you set
for a particular certificate profile. You can even set up the same method of authentication
and associated more than one form with it. You might do this if you wanted to change other
aspects of the enrollment.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...