Diagnostics
453
its operations. Before installing and configuring the clone, the master subsystem must be installed,
fully configured, and running.
A cloned subsystem is configured through standard configuration wizard. Before going through the
setup process, some manual preparation is required. To prepare for cloning, do the following:
•
If the keys and certificates are stored in the Internal Key Storage Token (software token).
When configuring the master instance, select
yes
in the
Export Keys and Certificates
panel to
back up the keys and certificates, and enter the password to protect the PKCS #12 file. Then restart
the master instance when configuration is complete.
If the keys and certificates were not backed up when the master instance was configured, they can
be backed up using the
pk12util
tool.
When configuring the clone instance, enter the location and the password for the PKCS #12 file in
the
Restore Keys and Certificates
screen. Then restart the clone instance when configuration is
complete.
•
If the keys and certificates are stored on a hardware token.
• Duplicate all the required keys and certificates, except the SSL server key and certificate to the
clone instance. Keep the nicknames for those certificates the same. Additionally, copy all the
necessary trusted root from the master instance to the clone instance.
• If the token is network-based, then the keys and certificates simply need to be available to the
token; the keys and certificates do not need to be copied.
• When using a network-based hardware token, make sure the high-availability feature is enabled
on the hardware token to avoid single point of failure.
20.2.1. Diagnostics
Use the
certutil
tool to list all the certificates in the clone instance to make sure that all the required
certificates are in place.
20.3. Testing the Cloned Configuration
To test the CA clone, do the following:
1. Request a certificate from the cloned CA.
2. Approve the request.
3. Download the certificate to the browser.
4. Revoke the certificate.
5. Check master CA's CRL for the revoked certificate. In the master Certificate Manager's agent
services page, click
Update Certificate Revocation List
. Find the CRL in the list.
The CRL should show the certificate revoked by the cloned Certificate Manager. If that certificate
is not listed, check logs to resolve the problem.
To test the OCSP clone, do the following:
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...