Managing the Certificate Database
Chapter
7
Administrative Basics
293
Whether you use an internal token or an external token for generating and storing
key pairs, CMS always maintains its list of trusted and untrusted CA certificates in
its internal token.
You may need to add new certificates to the database, remove unwanted
certificates from the database, or change the trust settings of CA certificates in the
database. This section explains how to view the contents of the certificate database,
delete unwanted certificates, and change the trust settings of CA certificates
installed in the database using the CMS window. For information on adding
certificates to the database, see “Certificate Setup Wizard” on page 296.
Viewing and Deleting Certificate Database
Content
As an administrator, you should periodically check the contents of the certificate
database and make sure that it doesn’t include any unwanted CA certificates. For
example, if the database includes CA certificates that you don’t ever want to trust
in your PKI setup, you should delete them.
Removing unwanted certificates also reduces the size of the certificate database.
To view the contents of the database:
1.
Log in to the CMS window (see “Logging Into the CMS Console” on page 245).
2.
Select the Configuration tab, and then in the right pane, select the Encryption
tab.
NOTE
CMS also provides a command-line utility called
certutil
for
managing its certificate database. For details about this tool, check
this site:
http://www.mozilla.org/projects/security/pki/nss/tools/
NOTE
When deleting CA certificates from the certificate database, be
careful not to delete the intermediate CA certificates, which help a
subsystem chain up to the trusted CA certificate. If in doubt, leave
the certificates in the database as untrusted CA certificates; see
“Changing the Trust Settings of a CA Certificate” on page 294.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...