
Agent Certificates
Chapter 9
Authorization
327
Getting an Agent’s Certificate from a Public CA
The following general guidelines explain how a user can get a client certificate from a
public CA and how you can copy that certificate (in base-64 encoded form) to the internal
database of the appropriate subsystem:
1.
Have the user send a client certificate request to a public CA from the computer they
will use to access the subsystem from the Agent Services interface. It is important that
they generate and submit this request from the computer they will use later to access
the subsystem, because part of this request process generates a private key on the local
machine. Alternatively, if location independence is required, they can use a hardware
token, such as a smart card, to generate and store the key pair (and the certificate when
they receive it from the public CA).
2.
When they receive the certificate from the public CA, have them import the certificate
into the web browser used to access the subsystem. It is a good idea to ask the user to
inform you that the certificate has been installed.
3.
Ask the user to send you the certificate information sent by the public CA. In the
information that you receive, locate the user’s certificate in base-64 encoded form.
You can also get the user’s certificate from the public CA that issued it. Access the
public CA site, search for the user’s certificate, and locate the certificate in base-64
encoded form.
4.
Copy the base-64 encoded certificate, including the
-----BEGIN
CERTIFICATE-----
and
-----END CERTIFICATE-----
marker lines, to a text file.
5.
Save the text file and use it to store a copy of the certificate in a subsystem’s internal
database. See “Setting up Administrators, Agents, and Auditors,” on page 318
Getting an Agent’s Certificate from Certificate
System
The following general instructions explain how a user can get a client certificate from CS
and how you can copy that certificate (in base-64 encoded form) to the internal database of
a subsystem:
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...