Configuring the Certificate Manager
112
Netscape Certificate Management System Administrator’s Guide • February 2003
Getting a CRL Signing Key Pair and Certificate
A Certificate Manager uses the key pair corresponding to the CA signing certificate
for signing certificates and certificate revocation lists (CRLs).
If you want a Certificate Manager to use a separate key pair for signing the CRLs it
generates, you can do so after installation. Note that a Certificate Manager’s CRL
signing certificate must be signed or issued by itself; make sure you submit the
request to the Certificate Manager itself.
To enable a Certificate Manager to sign CRLs with a separate key pair:
1.
Request and install a CRL signing certificate for the Certificate Manager. To do
this, you may use either of these options:
❍
Use the Certificate Setup Wizard available within the CMS window.
❍
Use the Certificate Database tool (
certutil
) to generate a key pair, request
a certificate for the key pair, and install the certificate in the Certificate
Manager’s certificate database. For more information about the Certificate
Database tool, see:
http://www.mozilla.org/projects/security/pki/nss/tools/
To request and install a CRL signing certificate for a Certificate Manager using
its Certificate Setup Wizard, follow these instructions:
a.
Log in to the CMS console (see “Logging Into the CMS Console” on
page 247).
b.
Select the Configuration tab, and then select the Encryption tab.
c.
Click Certificate Setup Wizard to launch the wizard.
d.
Select the option to request a certificate and then follow the on-screen
prompts to generate a certificate request for the CRL signing certificate—in
the Certificate Selection window, select
Other
and specify
caCrlSigning
as the certificate type in the associated text field.
e.
Once you have the certificate request ready, submit it to the Certificate
Manager so that it can issue a certificate—in the request submission screen
of the wizard, use the auto-submission feature by entering the Certificate
Manager’s hostname and port number so that the request gets added to the
Certificate Manager’s agent queue.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...