Using Secure Sockets Layer (SSL)
130
Netscape Enterprise Server Administrator’s Guide
Guidelines for Installing a PKCS#11 Module
Even though you install an external PKCS#11 module, you still must create a
Trust Database using the Internal (software) module. The PKCS#11 and SSL
code relies on the default certificate and key databases.
If you do not create a Trust Database (using the Security tab “Create Database”
link), one will be created for you when you request or install a certificate for an
external PKCS#11 module. However, when a module is created for you, it has
no password and cannot be accessed. This means that your external module
will continue to work, but that you will not be able to create and install server
certificates using the internal PKCS#11 module in the future.
For reference: If you allow a default database to be created without a password
and later discover you want to use the internal PKCS#11 module, you can
simply delete the existing database files:
$SERVER_ROOT/alias/https-$HOSTNAME-$SERVERID-key3.db
$SERVER_ROOT/alias/https-$HOSTNAME-$SERVERID-cert7.db
For example, for the server named
secure.example.com
installed in
/usr/local/netscape
the files would be:
/usr/local/netscape/alias/https-secure.example.com-secure-key3.db
/usr/local/netscape/alias/https-secure.example.com-secure-cert7.db
After deleting the existing databases, you can re-create them using the Security
tab “Create Database” link.
If you install a certificate for your server into an external PKCS#11 module (for
example, a hardware accelerator), the server will not be able to start using that
certificate until you manually edit
magnus.conf
.
The server always tries to start with the certificate named “Server-Cert.”
However, certificates in external PKCS#11 modules include one of the module’s
token names in their identifier. For example, a sever certificate installed on an
external smartcard reader called “smartcard0” would be named
“smartcard0:Server-Cert.”
Summary of Contents for Netscape Enterprise Server
Page 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Page 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Page 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Page 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Page 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Page 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Page 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Page 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Page 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Page 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Page 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Page 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Page 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Page 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Page 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Page 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Page 504: ...504 Netscape Enterprise Server Administrator s Guide ...