
5
Review the summary. YaST displays the current settings for confirmation. Click
Create. The root CA is created then appears in the overview.
TIP
In general, it is best not to allow user certificates to be issued by the root CA.
It is better to create at least one sub-CA and create the user certificates from
there. This has the advantage that the root CA can be kept isolated and secure,
for example, on an isolated computer on secure premises. This makes it very
difficult to attack the root CA.
17.2.2 Changing Password
If you need to change your password for your CA, proceed as follows:
1
Start YaST and open the CA module.
2
Select the required root CA and click Enter CA.
3
Enter the password if you entered a CA the first time. YaST displays the CA key
information in the Description tab (see
Figure 17.2
).
4
Click Advanced and select Change CA Password. A dialog box opens.
5
Enter the old and the new password.
6
Finish with OK
17.2.3 Creating or Revoking a Sub-CA
A sub-CA is created in exactly the same way as a root CA.
NOTE
The validity period for a sub-CA must be fully within the validity period of the
“parent” CA. A sub-CA is always created after the “parent” CA, therefore, the
204
Security Guide
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......