Tokens for Storing CMS Keys and Certificates
Chapter
7
Administrative Basics
317
Managing Tokens Used by the Subsystems
There are two main tasks involved in managing the tokens used by Certificate
Management System:
•
Viewing Tokens
•
Changing a Token’s Password
Viewing Tokens
To view a list of the tokens currently installed for a CMS instance:
1.
Log in to the CMS window (see “Logging Into the CMS Console” on page 245).
2.
Select the Configuration tab, and then in the right pane, select the Encryption
tab.
3.
In the Map To section, check the Token drop-down list.
It shows the names (as specified when the tokens were installed) of external
tokens installed for the currently selected CMS instance. For information on
installing external tokens, see “External Token” on page 314.
Changing a Token’s Password
The token, internal or external, that stores the key pairs and certificates for the
subsystems is protected (encrypted) by a password. To decrypt the key pairs or to
gain access to them, you must enter that password. The first time you specified this
password is when you used the token the first time, most likely during CMS
installation.
It is good security practice to periodically change the password that protects your
server’s keys and certificates; changing the password periodically minimizes the
risk of someone finding out the password. To change a token’s password, use the
certutil
command-line utility, the documentation for which can be found at this
site:
http://www.mozilla.org/projects/security/pki/nss/tools/
Note that the single sign-on password cache stores the passwords for tokens in
order to start the server using a single password; for details, see “Starting,
Stopping, and Restarting CMS Instances” on page 252. Whenever you change the
password, the cache is updated with the new password.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...