Configuring the Certificate Manager
118
Netscape Certificate Management System Administrator’s Guide • February 2003
The serial number range enables you to deploy multiple CAs, balancing the
number of certificates each CA issues. Note that the combination of an issuer
name and a serial number uniquely identifies a certificate. To ensure that two
distinct certificates issued by the same authority doesn’t contain the same serial
number, make sure the serial number range does not overlap among cloned
CAs.
Also note that when a CA exhausts all its serial numbers, you can revive it by
changing the values in the “Next serial number” and “Ending serial number”
fields, followed by restarting the Certificate Manager.
Default Signing Algorithm section.
Specifies the signing algorithm the
Certificate Manager should use for signing certificates. The choices are “MD2
with RSA”, “MD5 with RSA”, and “SHA1 with RSA”, if the CA’s signing key
type is RSA and “SHA1 with DSA”, if the CA’s signing key type is DSA.
Note that the signing algorithm specified in the Certificate Manager’s policy
configuration or certificate profile configuration overrides the algorithm you
select here.
4.
To save your changes, click Save.
Setting Up Authentication
The first step in configuring enrollment is setting up authentication. You can set up
more than one type of authentication. Each type you set up must be associated with
a particular form in the interface. If you are using the certificate profile feature for
enrollments, the forms are dynamically generated with the content being
determined by the inputs you set for a particular certificate profile. You can even
set up the same method of authentication and associated more than one form with
it. You might do this if you wanted to change other aspects of the enrollment.
For example, you might want to create an automated enrollment that requires
LDAP authentication. You have two classes of employees, permanent and
temporary. You want to issue both classes of employees certificates using LDAP
authentication, but you want to issue each of these classes certificates with different
validity periods and different extensions. You can create two different forms, both
using LDAP authentication, but each having different policies associated with the
form.
You can configure the enrollment method to be agent-approved or automated.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...