Managing the Certificate Database
302
Netscape Certificate Management System Administrator’s Guide • February 2003
To generate a certificate request based on an existing key pair, select the
token that contains the key pair you want to use for generating the request.
The wizard automatically selects the key pair that corresponds to the
certificate you chose in the previous step.
❍
If you want a new certificate, use a new key pair for generating the request.
For example, you may want to get a new SSL server certificate or may want
to replace an existing certificate whose private key has been compromised.
To generate a certificate request based on a new key pair, select the token
that can generate the key pair you want to use for generating the request.
For example, if you want to generate the key pair using an external
cryptographic device, such as a smart card, select that as the token. In
addition, you will be required to indicate details, such as the key algorithm
and size for the key pair.
•
The type and length of the key pair—you are required to provide this
information only if you chose to generate the certificate request based on a new
key pair. For key type, you can choose RSA or DSA. Be sure to select a key type
that the CA (to which you will later submit the request for signing) can certify.
For key length, enter the size in bits.
❍
If the key type is RSA, the key size can be 512, 768, 1024, 2048, 4096, or
Custom.
❍
If the key type is DSA, the key size can be 512, 1024, or Custom (which
must be in increments of 64 bit).
Keep in mind that generating a new key pair takes time—the longer the key
length the longer the time the wizard takes to generate it.
Step 4. Specify the Subject Name for the Certificate
Specify the subject name, in distinguished name (DN) format, for the certificate to
be requested. Note that you will see this screen only if you chose to generate the
certificate for a new key pair.
You can either enter values for individual DN attributes required to build the
subject DN or build the complete subject DN string yourself. If you enter values for
individual DN attributes, the wizard constructs the subject DN string.
If you want to enter values for individual DN components, provide the following
information:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...