
NOTE: Check your Valid Period
Take into account that the valid period must be lower than the valid
period in the root CA.
6
Select the Certificates tab. Reset compromised or otherwise unwanted sub-CAs
here using Revoke. Revocation is not enough to deactivate a sub-CA on its own.
Also publish revoked sub-CAs in a CRL. The creation of CRLs is described in
Section 17.2.6, “Creating CRLs”
(page 209).
7
Finish with OK
17.2.4 Creating or Revoking User
Certificates
Creating client and server certificates is very similar to creating CAs in
Section 17.2.1,
“Creating a Root CA”
(page 202). The same principles apply here. In certificates intended
for e-mail signature, the e-mail address of the sender (the private key owner) should
be contained in the certificate to enable the e-mail program to assign the correct certifi-
cate. For certificate assignment during encryption, it is necessary for the e-mail address
of the recipient (the public key owner) to be included in the certificate. In the case of
server and client certificates, the hostname of the server must be entered in the Common
Name field. The default validity period for certificates is 365 days.
To create client and server certificates, do the following:
1
Start YaST and open the CA module.
2
Select the required root CA and click Enter CA.
3
Enter the password if entering a CA for the first time. YaST displays the CA key
information in the Description tab.
4
Click Certificates (see
Figure 17.3
).
206
Security Guide
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......