Getting New Certificates for the Subsystems
Chapter
14
Managing CMS Keys and Certificates
487
Before getting a new self-signed certificate for the Certificate Manager,
therefore, you must address issues involved in deploying the new root CA
certificate across your enterprise. It is beyond the scope of this document to
explain how you should deploy the new CA certificate. You may find it useful
to go over some of the deployment issues discussed in the document available
at this URL:
http://help.netscape.com/kb/corporate/19980710-25.html
•
If you have deployed a Certificate Manager as a subordinate CA (that’s
chained to a root CA) and if you want to get a new subordinate CA certificate
for that Certificate Manager, you must consider the possible effects on your
PKI setup of changing the key pair of the subordinate CA. When you change
the subordinate CA key, all certificates that rely on the subordinate CA
certificate for validation will no longer be validated. Before getting a new
subordinate certificate, therefore, you must plan to address issues involved in
deploying the new subordinate CA certificate across you enterprise.
•
If you have deployed a Certificate Manager and if you have configured it to
publish CRLs to a Online Certificate Status Manager, you will need to identify
the Certificate Manager to the Online Certificate Status Manager again. For
details, see “Step 3. Identify the CA to the OCSP Responder” on page 711.
•
If you want to get a new signing certificate for a Registration Manager, check
whether the Registration Manager has been set up as a trusted manager for a
Certificate Manager and Data Recovery Manager—that is, you must identify
the subsystems that have been configured to receive requests from this
Registration Manager; see “Trusted Managers” on page 394. You will need to
replace the existing signing certificate with the new one in all these
subsystems.
•
If you want to get a new transport certificate for a Data Recovery Manager, you
must identify the end-entity interfaces or forms that have been set up for the
archival of end users’ encryption private keys; see “How Key Archival Works”
on page 739. You will need to replace the existing transport certificate with the
new one in all these forms.
•
If you want to get a new SSL server certificate for a Certificate Manager,
determine whether the Certificate Manager is used as a master CA in a
cloned-CA setup; see “Cloning a Certificate Manager” on page 286. If it is,
you’ll have to update the clone CAs certificate databases with the new SSL
server certificate.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...