Online Certificate Status Manager Deployment Considerations
Chapter
5
OCSP Responder
173
You submit this request either to a CMS CA, or you submit the request to a third
party public CA and then install the certificate you receive from the CA during the
rest of the installation. If you submit the request to a CMS CA, the installation
program will allow you submit the request to the CA in the install wizard, and pick
up the certificate once it is approved.
OCSP Signing Key Pair and Certificate
Every Online Certificate Status Manager you have installed has a certificate,
identified as the Online Certificate Status Manager signing certificate, whose public
key corresponds to the private key the Online Certificate Status Manager uses to
sign OCSP responses before sending them to OCSP-compliant clients. The Online
Certificate Status Manager’s signature provides persistent proof to an
OCSP-compliant client that the Online Certificate Status Manager has processed
the request. The first time you generated this certificate is when you installed the
Online Certificate Status Manager. The default nickname for the certificate is
ocspSigningCert cert-<instance_id>
, where
<instance_id>
identifies the
CMS instance in which the Online Certificate Status Manager is installed.
The Online Certificate Status Manager’s signing certificate was issued by the CA to
which you submitted the certificate signing request.
SSL Server Key Pair and Certificate
Every Online Certificate Status Manager you have installed has at least one SSL
server certificate. The first time you generated this certificate is when you installed
the Online Certificate Status Manager. The default nickname for the certificate is
Server-Cert cert-<instance_id>
, where
<instance_id>
identifies the CMS
instance in which the Online Certificate Status Manager is installed.
The Online Certificate Status Manager’s SSL server certificate was issued by the CA
to which you submitted the certificate signing request. You might have submitted
the request to an internally deployed CA or a public CA.
The Online Certificate Status Manager uses its SSL server certificate to do SSL
server-side authentication for the Online Certificate Status Manager Agent Services
interface.
By default, the Online Certificate Status Manager uses a single SSL server
certificate for authentication purposes. However, you can request and install
additional SSL server certificates for the Online Certificate Status Manager. For
example, you can configure the Online Certificate Status Manager to use separate
server certificates for the Netscape Console and the Online Certificate Status
Manager Agent Services interfaces. For instructions, see “Configuring the Server’s
Security Preferences” on page 320.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...