Keys and Certificates for the Main Subsystems
442
Netscape Certificate Management System Installation and Setup Guide • October 2001
The Certificate Manager’s SSL server certificate was issued by the CA to which you
submitted the certificate signing request. You might have submitted the request to
the Certificate Manager itself, another internally deployed CA, or a public CA. To
find out the issuer name, follow the instructions in “Viewing the Certificate
Database Content” on page 502.
The Certificate Manager uses its SSL server certificate to do SSL server-side
authentication to the following:
•
The End-Entity Services interface (the HTTPS port)
•
The Certificate Manager Agent Services interface
•
Clone Certificate Managers, when used as a master Certificate Manager in a
cloned CA setup (see “Cloning a Certificate Manager” on page 286)
By default, the Certificate Manager uses a single SSL server certificate for
authentication purposes. However, you can request and install additional SSL
server certificates for the Certificate Manager. For example, you can configure the
Certificate Manager to use separate server certificates for authenticating to the
End-Entity Services interface and Agent Services interface. For instructions, see
“Configuring the Server to Use Separate SSL Server Certificates” on page 478.
If you configure the Certificate Manager for SSL-enabled communication with a
publishing directory, the Certificate Manager also uses its SSL server certificate for
SSL client authentication to the publishing directory. This is the default
configuration. You can configure the Certificate Manager to use an alternate
certificate for this purpose; see “Getting an SSL Client Certificate for a Subsystem”
on page 480.
If you configure the Certificate Manager to function as a trusted manager to a Data
Recovery Manager, the Certificate Manager also uses its SSL server certificate for
SSL client authentication to the Data Recovery Manager. For details on trusted
managers, see “Trusted Managers” on page 394. You can also configure the
Certificate Manager to use an alternate certificate for this purpose; see “Getting an
SSL Client Certificate for a Subsystem” on page 480.
NOTE
If you have installed the Certificate Manager with a Data Recovery
Manager, both subsystems use the same SSL server certificate.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...