Agent Certificates
Chapter
8
Authorization
341
3.
When the user receives the certificate, the user must import the certificate into
the web browser they will use to access the subsystem. It is a good idea to ask
the user to inform you that the certificate has been installed.
After the user imports the certificate into the web browser, you need to copy
the certificate (in base-64 encoded form) in order to be able to add it to a
subsystem’s internal database.
4.
Access the end entities interface.
5.
Click the Retrieval tab.
6.
In the left frame, click either the List Certificates or Search For Certificates link,
and search for the user’s certificate.
7.
In the page listing the results of your search, click the Details button (next to
the corresponding user’s entry) to see detailed information about the
certificate.
8.
Scroll down to the Installing This Certificate in a Client section containing the
user’s certificate in base-64 encoded form.
9.
Copy the base-64 encoded certificate, including the
-----BEGIN
CERTIFICATE-----
and
-----END CERTIFICATE-----
marker lines, to a text
file.
10.
Save the text file and use it to store a copy of the certificate in a subsystem’s
internal database. See “Setting up Administrators, Agents, and Auditors,” on
page 330.
Revocation Status Checking of Agent
Certificates
You can configure a Certificate Manager and Registration Manager to check the
revocation status of an agent’s certificate the server receives during SSL client
authentication. You can configure a Data Recovery Manager (or Online Certificate
Status Manager) to check the revocation status of its agents’ certificates only if you
have deployed an OCSP responder and have issued agent certificates with
Authority Information Access extension pointing to the OCSP responder. For
information about adding Authority Information Access extension to certificates,
see “Configuring Policy Rules for a Subsystem” on page 491. For information about
setting up an OCSP responder, see Chapter 5, “OCSP Responder.”
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...