Registration Manager Deployment Considerations
136
Netscape Certificate Management System Administrator’s Guide • February 2003
You submit this request either to a CMS CA, or you submit the request to a third
party public CA and then install the certificate you receive from the CA during the
rest of the installation. If you submit the request to a CMS CA, the installation
program will allow you submit the request to the CA in the install wizard, and pick
up the certificate once it is approved.
When you get the certificates from a CMS CA, you can set the Registration
Manager up as a trusted manager of the Certificate Manager by specifying this on
the agent approval form for the certificate request. Otherwise, you will need to
manually set up the trusted relationship.
About the Registration Manager’s Key Pairs and Certificates
This section describes the key pairs and certificates associated with the Registration
Manager.
Signing Key Pair and Certificate
Every Registration Manager you install has a certificate, identified as the
Registration Manager signing certificate, whose public key corresponds to the private
key the Registration Manager uses to authenticate itself to the Certificate Manager.
This certificate is created and installed when you install the Registration Manager.
The default nickname for the certificate is
raSigningCert cert-<instance_id>
,
where
<instance_id>
identifies the CMS instance in which the Registration
Manager is installed.
The Registration Manager’s signing certificate was issued by the CA to which you
submitted the certificate signing request.
If you configure the Registration Manager to function as a trusted manager to
another subsystem, the Registration Manager uses its signing certificate for SSL
client authentication to the subsystem; this is the default configuration.
SSL Server Key Pair and Certificate
Every Registration Manager you install has at least one SSL server certificate. The
first time you generated this certificate is when you installed the Registration
Manager. The default nickname for the certificate is
Server-Cert cert-<instance_id>
, where
<instance_id>
identifies the CMS
instance in which the Registration Manager is installed.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...