Chapter 4
Configuring Centralized Keystores
103
To configure the
scakiod
service to use CKS, the following properties must be
created or modified. See
TABLE 4-2
for how to configure these properties:
■
Location of the LDAP server or servers (defined in the
config/serverlist
option)
■
Authentication credentials (defined with the
config/binddn
option)
■
Location of the keystore in the directory server (defined with the
config/basedn
option)
■
The method of authentication for the agent (defined with the
config/authtype
option)
■
The SSL certificate database path (defined with the
config/certdb
option)
■
For the
clientauth
authentication method, the name of the certificate used in
SSL client certificate authentication (defined with the
config/certname
option)
■
For the
simple
authentication method, the password (defined with the
passfile
option)
certdb
Specifies the SSL certificate database path. If
scakiod
is going to
communicate with the LDAP server over SSL, you must create a
certificate database path in this directory. If SSL is not configured, this
property is ignored and does not need to be set. The default value is:
/var/sca/private
for Oracle Solaris systems and
/var/opt/sun/sca6000/private
on Linux.
certname
Contains the name of the certificate used in SSL client certificate
authentication. If
clientauth
is selected as the authentication type,
you must specify the certificate name in this property. If client
certificate authentication (
clientauth
) is not being used, this
property is ignored and does not need to be set. The default value is
the name
authCert
.
passfile
For
scakiod
to authenticate with
simple
authentication, you must
place the password in the file pointed to by this property. The default
value is:
/var/sca/private/scakiod-pass.conf
on Oracle
Solaris systems and
/var/opt/sun/sca6000/private
on Linux. If
you choose
simple
authentication, this password must be the
password set for the agent entry when created using the
scakscfg
utility. If client certificate authentication is selected, this password
should be the password for the key database that exists at the location
specified in the
certdb
property.
TABLE 4-2
scakiod
Service Configuration Options
(Continued)
Property Name
Description
Summary of Contents for Crypto Accelerator 6000 Board
Page 1: ...Sun Crypto Accelerator 6000 Board Version 1 1 User s Guide Part No E39851 01 February 2013...
Page 16: ...xvi Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 18: ...xviii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 21: ...Preface xxi...
Page 22: ...xxii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 54: ...32 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 118: ...96 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 210: ...188 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 228: ...206 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 242: ...220 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 256: ...234 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 260: ...238 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 266: ...244 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...