
106
Sun Crypto Accelerator 6000 Board User’s Guide for Version 1.1 • February 2013
Note –
The following example is for Oracle Solaris. For Linux, use the
/var/opt/sun/sca6000/private
path instead of
/var/sca/private
.
Note –
The password specified here does not need to match the password used in
the password configuration file if simple authentication over SSL is to be used. The
password in
scakiod-pass.conf
should still match the password set for the agent
entry in the LDAP server. The password set for the certificate database will only be
important if SSL client certificate authentication is used.
2. Add the root CA certificate to the database.
Note –
The following example is for Oracle Solaris. For Linux, use the
/var/opt/sun/sca6000/private
path instead of
/var/sca/private
.
Note –
certname
is a friendly name for the CA certificate.
certpath
is the path to the
actual certificate file. Use the
-a
option only if the certificate is encoded in ASCII
form. If the certificate is in binary DER encoding, omit the
-a
option.
3. Set the ownership on the certificate and key databases to
daemon
.
4. (Oracle Solaris) Change the URL for the LDAP server in the
serverlist
to
indicate that it is using SSL
#
certutil -N -d /var/sca/private
Enter a password which will be used to encrypt your keys.
The password should be at least 8 characters long,
and should contain at least one non-alphabetic character.
Enter new password:
Re-enter password:
#
certutil -A -d /var/sca/private -n
certname
-t "CT,CT,CT" -a -i
certpath
#
chown daemon:sys cert8.db key3.db secmod.db
#
svccfg -s scakiod setprop config/serverlist=astring:
ldaps://
host
[:
port
]
Summary of Contents for Crypto Accelerator 6000 Board
Page 1: ...Sun Crypto Accelerator 6000 Board Version 1 1 User s Guide Part No E39851 01 February 2013...
Page 16: ...xvi Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 18: ...xviii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 21: ...Preface xxi...
Page 22: ...xxii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 54: ...32 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 118: ...96 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 210: ...188 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 228: ...206 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 242: ...220 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 256: ...234 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 260: ...238 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 266: ...244 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...