Installing an Online Certificate Status Manager
Chapter
5
OCSP Responder
183
❍
Token.
Enter either
internal
(if you plan to use the internal/software
token) or the name of an external token to store the SSL server certificate
and key pair. If you have not previously initialized the token’s password,
you must do so in this screen. See “Tokens,” on page 175 for more
information.
❍
Key Type.
Choose RSA .
❍
Key Length.
Available key sizes for RSA are 512, 768, 1024, 2048, 4096, or
Custom. Available key sizes for DSA are 512, 1024, or Custom (which must
be in increments of 64 bits only).
See “Signing Key Type and Length” on page 175 for more information.
Click Next to continue.
18.
Subject Name for SSL Server Certificate.
Type the values for the subject DN
components; these values identify the Online Certificate Status Manager’s SSL
server certificate. The CN must be the fully-qualified host name of the machine
on which you’re installing the Online Certificate Status Manager.
Click Next to continue.
19.
Certificate Extensions for SSL Server Certificate.
Select the required
extensions. The default settings should work for most deployments. If
necessary, you can add an additional extension by pasting its base-64 encoding
in the space provided on this screen.
CMS provides command-line tools for generating extensions to include in CA
and other certificate requests. For details about these tools, check this directory:
<server_root>/bin/cert/tools
Note that the certificate extension text field accepts a single extension blob. If
you want to add multiple extensions, you should use the
ExtJoiner
program,
which is also provided in the
tools
directory. For details on using the
ExtJoiner
program, see Chapter 5, “Extension Joiner Tool” of CMS
Command-Line Tools Guide.
Click Next to continue.
20.
SSL Server Certificate Request Creation.
This is an informational screen that
tells you that the wizard has all the information required to generate the key
pair and certificate request. In the previous screen, if you chose to include the
Subject Key Identifier extension in the certificate, you’ll be given the choice to
select the format for the certificate request. Otherwise, the request format will
be PKCS #10.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...