Chapter 12.
273
Editing Configuration in the CS.cfg File
The primary configuration file for every subsystem is its
CS.cfg
file. This chapter covers basic
information about and rules for editing the
CS.cfg
file This chapter also describes some other useful
configuration files used by the subsystems, such as password and web services files.
12.1. Default File and Directory Locations for Certificate
System Subsystems
Certificate System servers consist of subsystems (which are
types
of servers) and instances.
Server subsystems are servers for a specific type of PKI function and are installed by the Certificate
System RPMs. This general subsystem information is contained in non-relocatable, RPM-defined
shared libraries, Java archive files, binaries, and templates. These are stored in a fixed location.
NOTE
There is an environment variable,
DONT_RUN_PKICREATE
, which stops the
pkicreate
script from running automatically after the subsystems are installed. This allows the
default instances to be installed in user-defined installation directories, instead of the
default locations in
/var/lib
. To use custom directory locations, install the subsystems
through the ISO image with this environment variable set to block the
pkicreate
script.
Server instances are somewhat relocatable and have user-specific default and customized forms and
data. Subsystem instances can be stored anywhere on a system.
When the Certificate System is first installed, one instance for each subsystem type is also installed.
The default information such as the port numbers, instance name, and configuration file location for
each subsystem (after being installed and going through the setup process) is listed in the following
sections.
12.1.1. Default CA Instance Information
The default CA configuration is listed in
Table 12.1, “Default CA Instance Information”
. Most of these
values are unique to the default instance; the default certificates and some other settings are true for
every CA instance.
Setting
Value
Standard Port
1
9180
Agents Port
1
9443
Secure End Users Port
1
9444
End-Entities Client Authentication Port
1
9446
Admin Port
1
9445
Tomcat Port
1
9701
Instance Name
pki-ca
Main Directory
/var/lib/pki-ca
Configuration Directory
/etc/pki-ca
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...