Configuring the Certificate Manager
Chapter
3
Certificate Manager
111
•
Members of the Auditor group can view the signed audit log, and can view
configuration settings, but cannot perform any other operations on
configuration settings and do not have access to the agent services interface.
•
Members of the Certificate Manager Agent group can view configuration
settings in the administrative interface, but cannot perform any other
operations on the configuration settings. They can perform all operations for
all tasks associated with the agent services interface. They are allowed to
communicate with the CA via the agent services port.
•
Members of the Trusted Manager group are allowed to communicate with the
Certificate Manager.
Managing Certificates and the Certificate
Database
The CA signing certificate, SSL encryption certificate, and OCSP signing certificate
are created and installed during the installation of the Certificate Manager. See
“Certificate Manager Certificates,” on page 85 for more information about these
certificates and the things you should consider before getting these certificates.
CMS contains a Certificate Wizard that allows you to create additional certificates,
or to renew or replace a certificate for the Certificate Manager. See “Certificate
Setup Wizard,” on page 298 for details of using the wizard and about renewing or
replacing a subsystem certificate.
Trust Settings and CA Certificates
The trusted database also contains the CA certificates for those CAs that the
subsystem trusts. If your subsystem has certificates from a CA or accepts
certificates that are issued by a CA, it must have a copy of those CA certificates in
the trusted database, and they must be configured as trusted, see “Changing the
Trust Settings of a CA Certificate,” on page 296 and “Installing a New CA
Certificate in the Certificate Database,” on page 297.
Certificate Chain
You may also need to install a certificate chain in the database to provide the chain
of CAs to a trusted CA. See “Installing a CA Certificate Chain in the Certificate
Database,” on page 298.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...