![Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 Скачать руководство пользователя страница 492](http://html1.mh-extra.com/html/netscape/netscape-management-system-4-5/netscape-management-system-4-5_installation-and-setup-manual_1674705492.webp)
Getting New Certificates for the Subsystems
492
Netscape Certificate Management System Installation and Setup Guide • October 2001
2.
Ensure that the CA that signed the Registration Manager’s certificate is in the
certificate database of the subsystem.
When a Registration Manager does SSL client authentication using its new
certificate, the subsystem, as a part of validating the certificate presented by the
Registration Manager, checks its trust database for the CA (certificate) that
signed the Registration Manager’s new certificate. If the subsystem does not
find the CA as a trusted CA in its trust database, it rejects the Registration
Manager.
For instructions on checking the trust database of a subsystem, see “Viewing
the Certificate Database Content” on page 502.
❍
If you don’t find the CA certificate, add it to the database as a trusted CA.
For instructions on adding a CA certificate to the trust database of a
subsystem, see “Installing a New CA Certificate in the Certificate
Database” on page 507.
❍
If you find the CA certificate, verify its trust status. If it is untrusted,
change the status to trusted. For instructions on changing the trust setting
of a CA certificate, see “Changing the Trust Settings of a CA Certificate” on
page 505.
Deploying Data Recovery Manager’s Transport Certificate
Because clients capable of generating dual key pairs use the transport certificate for
encrypting end users’ encryption private keys before sending them to the Data
Recovery Manager, you must update the appropriate enrollment or key archival
page to identify and use the new transport certificate. Otherwise, the Data
Recovery Manager will fail to archive users’ encryption private keys.
In general, here’s what you need to do:
1.
Locate the enrollment page that embeds the key archival feature.
2.
View the HTML source, and identify the parameter that corresponds to the
Data Recovery Manager’s transport certificate.
The default enrollment forms for end users embed this feature. Figure 14-2
shows the default directory-based user enrollment form with the transport
certificate-related information. (For more information, see “Step C. Customize
the Certificate Enrollment Form” on page 753.)
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...