Chapter 12. Managing Tokens
268
• For an nCipher HSM, do the following:
modutil -dbdir . -nocertdb -add nethsm -libfile /opt/nfast/toolkits/pkcs11/
libcknfast.so
12.3. Managing Tokens Used by the Subsystems
There are two main tasks involved in managing the tokens used by Certificate System:
• Viewing tokens
• Changing the token passwords
12.3.1. Viewing Tokens
To view a list of the tokens currently installed for a Certificate System instance, use the
modutil
utility.
1. Open the instance
alias
directory. For example:
cd /var/lib/rhpki-ca/alias
2. Show the information about the installed PKCS #11 modules installed as well as information on
the corresponding tokens using the
modutil
tool.
modutil -dbdir . -nocertdb -list
12.3.2. Changing a Token's Password
The token, internal or external, that stores the key pairs and certificates for the subsystems is
protected (encrypted) by a password. To decrypt the key pairs or to gain access to them, enter the
token password. This password is set when the token is first accessed, usually during Certificate
System installation.
It is good security practice to change the password that protects the server's keys and certificates
periodically. Changing the password minimizes the risk of someone finding out the password. To
change a token's password, use the
certutil
command-line utility.
For information about
certutil
, see
http://www.mozilla.org/projects/security/pki/nss/tools/
.
The single sign-on password cache stores token passwords in the
password.conf
file. This file must
be manually updated every time the token password is changed. For more information on managing
passwords through the
password.conf
file, see
Section 3.3, “System Passwords”
.
12.4. Detecting Tokens
To see if a token can be detected by Certificate System to be installed or configured, use the
TokenInfo
utility.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...