Online Certificate Status Manager Deployment Considerations
Chapter
5
OCSP Responder
175
Password Storage
Each subsystem stores passwords for its internal database, and for the tokens
containing its keys and certificates. See “System Passwords,” on page 252 for
information on how these passwords are stored.
Tokens
You choose either the
internal
token (if you plan to use the internal/software
token) or an external token to store the signing certificate and key pair and the SSL
signing certificate and key pair.
If you are using an external token, you will need to install it before you run the
Installation Wizard. In the wizard, you can select from a list of already installed
and available tokens. For example,
HSM
. For installation instructions, see “External
Token” on page 316.
Internal Database
Each subsystem uses an internal database to store information (such as certificates
and certificate requests) used by the subsystem you will be installing in this CMS
instance. By default, a separate internal database is created for each subsystem you
configure. You can choose to use the same internal database for more than one
subsystem by specifying this when running the installation wizard to configure
that subsystem. You should carefully consider whether you want to store this
information in a separate internal database for each subsystem or use one internal
database for all subsystems installed on the host.
It’s recommended that you do not use this Directory Server instance for any other
purposes; the directory schema will be configured for storing CMS data.
Signing Key Type and Length
If you wish, you can import the signing key and certificate used in a previous
version of CMS installation rather than generating a new signing key pair. For
information on how to do this, check the migration information in Step 6 of the
section “Upgrading” in Chapter 2 of the Command-Line Tools Guide.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...