Configuring a Registration Manager
154
Netscape Certificate Management System Administrator’s Guide • February 2003
Managing Certificates and the Certificate
Database
The signing certificate and SSL encryption certificate are created and installed
during the installation of the Registration Manager. See “Registration Managers
Certificates,” on page 135 for more information about these certificates and the
things you should consider before getting these certificates.
CMS contains a Certificate Wizard that allows you to create additional certificates,
or to renew or replace a certificate for the Registration Manager. See “Certificate
Setup Wizard,” on page 298 for details of using the wizard and about renewing or
replacing a subsystem certificate.
Trust Settings and CA Certificates
The trusted database also contains the CA certificates for those CAs that the
subsystem trusts. If your subsystem has certificates from a CA or accepts
certificates that are issued by a CA, it must have a copy of those CA certificates in
the trusted database, and they must be configured as trusted, see “Changing the
Trust Settings of a CA Certificate,” on page 296 and “Installing a New CA
Certificate in the Certificate Database,” on page 297.
Certificate Chain
You also may need to install a certificate chain in the database to provide the chain
of CAs to a trusted CA. You can install a certificate chain in the certificate database,
see “Installing a CA Certificate Chain in the Certificate Database,” on page 298.
Getting Additional SSL Server Certificates
The Registration Manager uses its SSL server certificate to do SSL server-side
authentication to the following:
•
The End-Entity Services interface (the HTTPS port)
•
The Registration Manager Agent Services interface
By default, the Registration Manager uses a single SSL server certificate for
authentication purposes. However, you can request and install additional SSL
server certificates for the Registration Manager. For example, you can configure the
Registration Manager to use separate server certificates for authenticating to
Netscape Console, the end entity services interface, and the Registration Manager
Agent Services interface. For instructions, see “Configuring the Server to Use
Separate SSL Server Certificates” on page 321.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...