Configuring a Registration Manager
152
Netscape Certificate Management System Administrator’s Guide • June 2003
Managing Certificates and the Certificate
Database
The signing certificate and SSL encryption certificate are created and installed
during the installation of the Registration Manager. See “Registration Managers
Certificates,” on page 133 for more information about these certificates and the
things you should consider before getting these certificates.
CMS contains a Certificate Wizard that allows you to create additional certificates,
or to renew or replace a certificate for the Registration Manager. See “Certificate
Setup Wizard,” on page 296 for details of using the wizard and about renewing or
replacing a subsystem certificate.
Trust Settings and CA Certificates
The trusted database also contains the CA certificates for those CAs that the
subsystem trusts. If your subsystem has certificates from a CA or accepts
certificates that are issued by a CA, it must have a copy of those CA certificates in
the trusted database, and they must be configured as trusted, see “Changing the
Trust Settings of a CA Certificate,” on page 294 and “Installing a New CA
Certificate in the Certificate Database,” on page 295.
Certificate Chain
You also may need to install a certificate chain in the database to provide the chain
of CAs to a trusted CA. You can install a certificate chain in the certificate database,
see “Installing a CA Certificate Chain in the Certificate Database,” on page 296.
Getting Additional SSL Server Certificates
The Registration Manager uses its SSL server certificate to do SSL server-side
authentication to the following:
•
The End-Entity Services interface (the HTTPS port)
•
The Registration Manager Agent Services interface
By default, the Registration Manager uses a single SSL server certificate for
authentication purposes. However, you can request and install additional SSL
server certificates for the Registration Manager. For example, you can configure the
Registration Manager to use separate server certificates for authenticating to
Netscape Console, the end entity services interface, and the Registration Manager
Agent Services interface. For instructions, see “Configuring the Server to Use
Separate SSL Server Certificates” on page 319.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...