Cloning the Online Certificate Status Manager
686
Netscape Certificate Manager System Administrator’s Guide • June 2003
3.
Make sure that you have already installed the agent certificate for the master
Online Certificate Status Manager. See “Agent Certificates” on page 335 for
more information about agent certificates.
4.
Also consider the following:
❍
OCSP’s signing key and certificate
—You must use the master Online
Certificate Status Manager’s signing key and certificate. If you do not use
the master Online Certificate Status Manager’s key and certificate
databases, the cloned Online Certificate Status Manager will need to
generate a new signing key and certificate; consequently, it will not be a
clone.
❍
OCSP’s SSL server key and certificate
—This depends on the way in
which you have deployed the clone environment. If you are using a load
balancer, regardless of whether or not the host machines are different, you
do not need to generate a new SSL server certificate for the cloned Online
Certificate Status Manager, since the SSL server certificate DN should
contain the hostname of the load balancer as the common name (CN)
attribute. If the cloned Online Certificate Status Manager uses the same
hostname as that of the master Online Certificate Status Manager and you
are not using a load balancer, you can use the same SSL server certificate
and key copied from the master. If you are not using a load balancer and
your master and cloned Online Certificate Status Managers exist on
separate machines (e. g. - a proprietary configuration which expects
usernames [A-M] using one machine and usernames [N-Z] using the other
machine), then the SSL server certificate DN's should contain the hostname
of their resident machines with their own unique keys obtained by using
the renewal process (this scenario requires advanced manual configuration
and therefore is not recommended).
For more detailed information about setting up the master Online Certificate Status
Manager, see “Configuring the Online Certificate Status Manager” on page 187.
Cloning the OCSP Responder
The following are the steps to setup cloning for an Online Certificate Status
Manager:
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...