Chapter 4
Configuring Centralized Keystores
111
Note –
The value for
agent-dn
must be the same as the value in the
binddn
SMF
property for the
scakiod
service.
2. Use
ldapmodify
to alter the agent entry and add the certificate:
Note –
dir-adm-dn
is the bind DN for a directory administrator or some directory
object with write access.
host
is the hostname where the directory is located.
3. In the directory server, ensure that the CA certificate used to sign the certificate
that
scakiod
uses for authentication is trusted.
The procedure for this will vary across different DS implentations. Refer to the
directory server documentation for details on how to do this.
4. Set up certificate mapping on the directory server.
The procedure for this will vary between DS implementations. The
certmap.conf
file for Sun directory servers contains a default mapping and zero
or more additional mappings tied to the issuer DN for certificates used in
authentication. If the default rule cannot be used, you might need to create a
separate rule for the issuer DN. That issuer DN will be the same as the issuer DN
for the certificate used by the
scakiod
service for SSL client certificate
authentication. In addition, set the
verifycert
directive to
on
for the mapping
rule you are modifying. In cases where the certificate subject name matches the
DN of the agent entry, the
DNComps
directive can be commented out. If the names
differ, then different combinations of the
DNComps
and
FilterComps
might be
required to get proper certificate mapping.
5. (Oracle Solaris) Restart the
scakiod
service:
6. (Linux) Start and stop the
sca
services:
#
ldapmodify -h
host
-b -D
dir-adm-dn
< modfile
modifying entry cn=geeky,ou=Agents,ou=scakeystore,o=SUN,c=US
#
svcadm restart scakiod
#
/etc/init.d/sca stop
#
/etc/init.d/sca start
Summary of Contents for Crypto Accelerator 6000 Board
Page 1: ...Sun Crypto Accelerator 6000 Board Version 1 1 User s Guide Part No E39851 01 February 2013...
Page 16: ...xvi Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 18: ...xviii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 21: ...Preface xxi...
Page 22: ...xxii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 54: ...32 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 118: ...96 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 210: ...188 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 228: ...206 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 242: ...220 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 256: ...234 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 260: ...238 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 266: ...244 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...