Step 4: Migrating Security Databases
For every Red Hat Certificate System subsystem instance migration, the data from the
certificate (
cert7.db
or
cert8.db
) and key (
key3.db
) security databases for the Netscape
Certificate Management System 6.x instances must be extracted and copied into the Red Hat
Certificate System 7.3 subsystem's
/alias
directory. Follow the migration procedure
corresponding to the subsystem being migrated.
There are three subsystems which can be migrated from Certificate Management System 6.x to
Red Hat Certificate System 7.3 — the CA, DRM, and OCSP — each with a different migration
procedure.
•
Section 1, “Certificate Authority (CA) Migration”
•
Section 2, “Data Recovery Manager (DRM) Migration”
•
Section 3, “Online Certificate Status Protocol Manager (OCSP) Migration”
1. Certificate Authority (CA) Migration
Determine if the migration to be performed involves software security databases, an HSM, or
both, and follow the appropriate process for the deployment scenario being migrated.
•
Section 1.1, “Option 1: Security Databases to Security Databases Migration”
•
Section 1.2, “Option 2: Security Databases to HSM Migration”
•
Section 1.3, “Option 3: HSM to Security Databases Migration”
•
Section 1.4, “Option 4: HSM to HSM Migration”
1.1. Option 1: Security Databases to Security Databases
Migration
1. Remove all the security databases in the Certificate System 7.3 server which will receive
migrated data.
rm /var/lib/instance_ID/alias/cert8.db
rm /var/lib/instance_ID/alias/key3.db
Chapter 5.
13