Requesting Certificates
233
11.2.1.2. Requesting a Subsystem, Server, or Signing Certificate through
the Console
The Certificate Setup Wizard for the different subsystems creates requests for any of the certificates
used by that subsystem. These certificates can be a server certificate, OCSP signing certificate, or
subsystem-specific certificate, such as a CA signing certificate or DRM transport certificate.
NOTE
It is important that the agent or user generate and submit the client request from the
computer that will be used later to access the subsystem because part of the request
process generates a private key on the local machine. If location independence is
required, the user can also use a hardware token, such as a smart card, to store the key
pair and the certificate.
To create a certificate request using the subsystem administrative console, do the following:
1. Open the subsystem console.
pkiconsole https://server.example.com:9443/ca
2. In the
Configuration
tab, select
System Keys and Certificates
in the navigation tree.
3. In the right panel, select the
Local Certificates
tab.
4. Click
Add/Renew
.
Figure 11.2. Certificate Request Wizard
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...