Managing the Certificate Database
298
Netscape Certificate Management System Administrator’s Guide • February 2003
When the Registration Manager attempts to request a service from the Certificate
Manager (using the renewed certificate for SSL client authentication), the
Certificate Manager fails to authenticate the Registration Manager. This happens
because, as a part of validating the certificate presented by the Registration
Manager, the Certificate Manager checks its certificate database for the CA that
signed the Registration Manager’s certificate. The Certificate Manager does not
find the CA listed in its trust database as a trusted CA, so it rejects the Registration
Manager’s service request.
The Certificate Setup Wizard built into the CMS window automates the process of
installing trusted CA certificates in the certificate database. For instructions on
using the wizard, see “Using the Wizard to Install a Certificate or Certificate
Chain” on page 309.
Installing a CA Certificate Chain in the Certificate
Database
Any client or server software that supports certificates maintains a collection of
trusted CA certificates in its certificate database. These CA certificates determine
which other certificates the software can validate—in other words, which issuers of
certificates the software can trust. In the simplest case, the software can validate
only certificates issued by one of the CAs for which it has a certificate. It’s also
possible for a trusted CA certificate to be part of a chain of CA certificates, each
issued by the CA above it in a certificate hierarchy; for details on certificate
hierarchies and certificate chains, see “How CA Certificates Are Used to Establish
Trust” in Appendix D of Managing Servers with Netscape Console.
Certificate Setup Wizard
CMS provides a wizard, called the Certificate Setup Wizard, which automates the
process of requesting and installing the certificates required by the CMS
manager—Certificate Manager, Registration Manager, Data Recovery Manager, or
Online Certificate Status Manager—installed in a CMS instance.
NOTE
Be sure to choose the “Other Trusted CAs” option in Step 2 of the
wizard process.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...