Online Certificate Status Manager Deployment Considerations
Chapter
5
OCSP Responder
173
Password Storage
Each subsystem stores passwords for its internal database, and for the tokens
containing its keys and certificates. See “System Passwords,” on page 250 for
information on how these passwords are stored.
Tokens
You choose either the
internal
token (if you plan to use the internal/software
token) or an external token to store the signing certificate and key pair and the SSL
signing certificate and key pair.
If you are using an external token, you will need to install it before you run the
Installation Wizard. In the wizard, you can select from a list of already installed
and available tokens. For example,
HSM
. For installation instructions, see “External
Token” on page 314.
Internal Database
Each subsystem uses an internal database to store information (such as certificates
and certificate requests) used by the subsystem you will be installing in this CMS
instance. By default, a separate internal database is created for each subsystem you
configure. You can choose to use the same internal database for more than one
subsystem by specifying this when running the installation wizard to configure
that subsystem. You should carefully consider whether you want to store this
information in a separate internal database for each subsystem or use one internal
database for all subsystems installed on the host.
It’s recommended that you do not use this Directory Server instance for any other
purposes; the directory schema will be configured for storing CMS data.
Signing Key Type and Length
If you wish, you can import the signing key and certificate used in a previous
version of CMS installation rather than generating a new signing key pair. For
information on how to do this, check the migration information in Step 6 of the
section “Upgrading” in Chapter 2 of the Command-Line Tools Guide.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...