Understanding CMS Installation
Appendix
C
Understanding the Common Criteria Evaluated CMS Setup
723
When you begin installation, you will be instructed to create a special user ID,
which you will then use to log in to the Operating System when you install CMS.
This user ID will be the effective user ID of the CMS server itself during runtime.
You will then need to create groups for the auditor and administrator roles, which
you must then assign to the actual user IDs for the CMS administrators and CMS
auditor users on the operating system.
After CMS files are installed, you will be instructed to change the ownership of the
CMS files to the special user ID that you’ve created by running a shell script
provided with this product. Finally, you will be instructed to disable this special
user ID account, preventing users from logging in with this user ID.
Understanding CMS Installation
You must install CMS on each host on which a CMS subsystem is installed. You
can set up the environment with all subsystems installed on the same host, or with
some or all subsystems on separate hosts, but every host must have CMS.
Configuring CMS to Use Hardware Tokens
You will be instructed to configure each CMS installation to use a FIPS 140-1 Level
3 certified hardware token after installing CMS on the host, but before installing
and configuring any subsystems on that host. Hardware tokens are required for all
subsystems (CA, RA, DRM, and OCSP Responder); DRM needs at least two: one
for user private key transport key, and one for user private key storage key.
Revocation Checking
In order to check the status of CMS user certificates, you will be instructed to set up
revocation checking for each CMS instance by setting up the revocation feature in
the NES instance used by that CMS instance.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...