Configuring the Certificate Manager
Chapter
3
Certificate Manager
115
If you want a Certificate Manager to use a separate key pair for signing the CRLs it
generates, you can do so after installation. Note that a Certificate Manager’s CRL
signing certificate must be signed or issued by itself; make sure you submit the
request to the Certificate Manager itself.
To enable a Certificate Manager to sign CRLs with a separate key pair:
1.
Request and install a CRL signing certificate for the Certificate Manager. To do
this, you may use either of these options:
❍
Use the Certificate Setup Wizard available within the CMS window.
❍
Use the Certificate Database tool (
certutil
) to generate a key pair, request
a certificate for the key pair, and install the certificate in the Certificate
Manager’s certificate database. For more information about the Certificate
Database tool, see:
http://www.mozilla.org/projects/security/pki/nss/tools/
To request and install a CRL signing certificate for a Certificate Manager using
its Certificate Setup Wizard, follow these instructions:
a.
Log in to the CMS console (see “Logging Into the CMS Console” on
page 245).
b.
Select the Configuration tab, and then select the Encryption tab.
c.
Click Certificate Setup Wizard to launch the wizard.
d.
Select the option to request a certificate and then follow the on-screen
prompts to generate a certificate request for the CRL signing certificate—in
the Certificate Selection window, select
Other
and specify
caCrlSigning
as the certificate type in the associated text field.
e.
Once you have the certificate request ready, submit it to the Certificate
Manager so that it can issue a certificate—in the request submission screen
of the wizard, use the auto-submission feature by entering the Certificate
Manager’s hostname and port number so that the request gets added to the
Certificate Manager’s agent queue.
f.
Log in to the Agent Services interface, check the request for required
extensions. For example, the CRL signing certificate must contain the Key
Usage extension with the
crlSigning
bit set. (By default, the Certificate
Manager’s policy is configured to add the Key Usage extension with
correct bits to the CRL signing certificate; see the policy rule named
CRLSignCertKeyUsageExt
, which is an instance of
KeyUsageExt
plug-in.)
g.
Approve the request.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...