529
where keys are stored, 175
key length, 113
key recovery, 177
designated agents
See key recovery agents, 177
how to set up, 179
key recovery agents
passwords, 177
significance, 177
responsibilities, 177
role defined, 177
KEYGEN tag, 22
keys
defined, 486
management and recovery, 504
keyUsage, 467
L
LDAP, 22
LDAP publishing
defined, 338
manual updates, 362
when to do, 362
who can do this, 362
linked CA, 8
load balancing, 452
location of
active log files, 76
log modules
deleting, 87
registering new ones, 87
logging
buffered vs. unbuffered, 81
log files
archiving rotated files, 82
default location, 76
signing rotated files, 86
timing of rotation, 81
log levels, 80, 80
default selection, 81
how they relate to message categories, 80
significance of choosing the right level, 81
what it means, 80
managing from Certificate System console, 85
services that are logged, 79
types of logs, 76
Audit, 76
Error, 78
M
mail server used for notifications, 67
managing
certificate database, 254
mapper modules
deleting, 363
registering new ones, 363
mappers
created during installation, 346, 367, 369
mappers that use
CA certificate, 367
DN components, 370
master CA, 14
modifying
privileged user's group membership, 399
N
Name extension modules
Issuer Alternative Name, 300
nameConstraints, 469
naming convention
for internal database instances, 106
netscape-cert-type, 482
nickname
for CA signing certificate, 111
for OCSP signing certificate, 112
for signing certificate, 159
for SSL server certificate, 112, 159
for wTLS signing certificate, 112
notifications
configuring the mail server
hostname, 67
port, 67
to agents about unpublishing certificates, 440
O
OCSP, 12
OCSP publisher, 366
OCSP responder, 157
defined, 12
OCSP server, 157
OCSP signing certificate, 112, 226
nickname, 112
requesting, 233
Online Certificate Status Manager
administrators
creating, 161, 394
agents
creating, 161, 394
introduced, 12
key pairs and certificates
signing certificate, 159
SSL server certificate, 159
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...