
Chapter 7.
95
Silent Configuration
The Certificate System includes a tool,
pkisilent
, which configures an instance in a single step.
Normally, instances are configured by accessing the subsystem HTML page and going through the
setup wizard.
pkisilent
can be used to pass all of the configuration parameters to a new instance
simply from the command line.
NOTE
The
pkisilent
script is downloaded and installed in its own package.
7.1. About pkisilent
Silent configuration
sets up a new subsystem instance in a single pass, by sending all of the
configuration parameters through the command line. For Certificate System subsystems, this is done
using the
pkisilent
command.
The
pkisilent
command can configure the subsystem instance the same as if it were configured
using the HTML-based configuration wizard, so it can create a new security domain or use an existing
one, back up keys, create a clone, or use certificates issued by an external CA.
From a high level, the
pkisilent
command has groups of parameters that define major areas of the
subsystem's default settings and users.
There are two template files that are shell scripts for silent configuration:
/usr/share/pki/silent/
pki_silent.template
and
/usr/share/pki/silent/subca_silent.template
. Both of
these templates have detailed information on parameters and usage options for
pkisilent
.
pkisilent Configure
type
-parameters to configure the subsystem URL
...
-parameters to
configure the admin user
...
-parameters to configure the domain
...
-parameters to configure
the agent
...
-parameters to configure the internal database
...
-parameters to configure the
subsystem keys, certificates, and key store
Example 7.1. pkisilent Command
The options available to use with the
pkisilent
command are listed in
Table 7.1, “Parameters for
pkisilent”
.
TIP
There are two template files that are shell scripts for silent configuration:
/usr/
share/pki/silent/pki_silent.template
and
/usr/share/pki/silent/
subca_silent.template
. Both of these templates have detailed information on
parameters and usage options for
pkisilent
.
To check the specific options for any
Configure
type
option, just run the
pkisilent
command with the
Configure
type
option and the
-help
flag. For example, to get the
help for configuring a subordinate CA:
pkisilent ConfigureSubCA -help
Summary of Contents for CERTIFICATE SYSTEM 8 - DEPLOYMENT
Page 5: ...v 9 5 7 Shared Certificate System Subsystem File Locations 119 Index 121 ...
Page 6: ...vi ...
Page 18: ...8 ...
Page 32: ...22 ...
Page 70: ...60 ...
Page 104: ...94 ...
Page 114: ...104 ...
Page 118: ...108 ...
Page 132: ...122 ...