Groups and Their Privileges
398
Netscape Certificate Management System Installation and Setup Guide • October 2001
When you set up a trusted manager for a CMS subsystem, it is important to know
which CA has issued the certificate the trusted manager will use for SSL client
authentication to the subsystem. The certificate must be issued by a CA that the
subsystem trusts. For example, when you set up a trusted Registration Manager for
a subsystem, it is important to know which CA has issued the Registration
Manager’s signing certificate. The certificate must be issued by a CA that the
subsystem trusts. If the subsystem is a Certificate Manager, the certificate must be
issued by either the Certificate Manager itself or a CA that the Certificate Manager
trusts. Similarly, if the Registration Manager is connected to a Data Recovery
Manager, the signing certificate must be issued by the CA that the Data Recovery
Manager trusts.
The issuer of a Registration Manager’s signing certificate is the CA from which you
requested the certificate when you installed the Registration Manager. If you have
renewed the certificate since installation, the issuer is the CA from which you
requested the renewed certificate. Check the signing certificate for its issuer’s
name; see “Viewing the Certificate Database Content” on page 502. You can also
find this information by looking at the installation worksheet you completed in
preparation for installing the system.
Once you learn the issuer’s name, verify that this CA’s certificate exists in the
subsystem’s trust database and that the certificate is trusted. To check whether the
CA’s certificate exists in the subsystem’s trust database, follow the instructions in
“Viewing the Certificate Database Content” on page 502.
•
If the CA’s certificate isn’t listed, follow the instructions in “Using the Wizard
to Install a Certificate or Certificate Chain” on page 471 and add the certificate
to the subsystem’s certificate database.
•
If the CA’s certificate is listed but untrusted, follow the instructions in
“Changing the Trust Settings of a CA Certificate” on page 505 and change the
trust setting to trusted.
Groups and Their Privileges
In Certificate Management System, a group refers to a collection of privileged
users—administrators, agents, or trusted Registration Managers. Each group has
predetermined privileges, based on its access control. All users belonging to a
group automatically inherit the privileges of that group.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...