228
OES 2 SP3: Planning and Implementation Guide
22.1.2 OES 2 Certificate Management
OES 2 enhances certificate management as follows:
“Installation of eDirectory Certificates” on page 228
“What Is Installed Where” on page 228
“Novell Certificate Server” on page 229
“Server Self-Provisioning” on page 229
“PKI Health Check” on page 229
Installation of eDirectory Certificates
As you install eDirectory and OES 2, by default all HTTPS services are configured to use
eDirectory certificates. This means that eDirectory is established as the Certificate Authority for the
tree you are installing into, and it will generate keys and certificates for the server and replace the
installed SLES certificates with the eDirectory certificates.
What Is Installed Where
Key and certificate files are installed in the following locations:
Table 22-1
File Locations
Location
Details
/etc/ssl/certs
This is the default location of trusted root certificates for clients
on the server.
Most of the applications on the server are configured to use
this directory. For example, the LDAP client uses one or more
of the trusted certificates in this directory when establishing a
secure LDAP connection.
The OES 2 installation copies the eDirectory tree CA’s
certificate (
eDirCACert.pem
) here, thereby establishing the
CA as a trusted root.
Everyone (other) has rights to read the contents of this
directory.
/etc/ssl/servercerts
The standard location for the server’s raw private key
(
serverkey.pem
) and certificates (
servercert.pem
).
Applications on the server, including OES 2 applications, are
configured to point to the files in this directory.
Only
root
and some specific groups can read the files in this
directory.
Содержание OPEN ENTERPRISE SERVER - CONVERSION GUIDE 12-2010
Страница 12: ...12 OES 2 SP3 Planning and Implementation Guide...
Страница 24: ...24 OES 2 SP3 Planning and Implementation Guide...
Страница 50: ...50 OES 2 SP3 Planning and Implementation Guide...
Страница 74: ...74 OES 2 SP3 Planning and Implementation Guide...
Страница 78: ...78 OES 2 SP3 Planning and Implementation Guide...
Страница 80: ...80 OES 2 SP3 Planning and Implementation Guide...
Страница 96: ...96 OES 2 SP3 Planning and Implementation Guide...
Страница 146: ...146 OES 2 SP3 Planning and Implementation Guide...
Страница 176: ...176 OES 2 SP3 Planning and Implementation Guide...
Страница 210: ...210 OES 2 SP3 Planning and Implementation Guide...
Страница 218: ...218 OES 2 SP3 Planning and Implementation Guide...
Страница 226: ...226 OES 2 SP3 Planning and Implementation Guide...
Страница 234: ...234 OES 2 SP3 Planning and Implementation Guide...
Страница 236: ...236 OES 2 SP3 Planning and Implementation Guide...
Страница 244: ...244 OES 2 SP3 Planning and Implementation Guide...
Страница 246: ...246 OES 2 SP3 Planning and Implementation Guide...
Страница 250: ...250 OES 2 SP3 Planning and Implementation Guide...
Страница 254: ...254 OES 2 SP3 Planning and Implementation Guide...
Страница 258: ...258 OES 2 SP3 Planning and Implementation Guide...
Страница 284: ...284 OES 2 SP3 Planning and Implementation Guide...
Страница 286: ...286 OES 2 SP3 Planning and Implementation Guide...
Страница 294: ...294 OES 2 SP3 Planning and Implementation Guide...