370
Novell ZENworks Network Access Control Users Guide
no
vd
ocx
(e
n)
24
Ma
rch 20
09
3
keytool
prompted for the password for the
<keystore_filename>
file, which is the password
used when the keystore was created.
4
Submit the CSR (see
Section 1.9, “Copying Files,” on page 28
) to your chosen CA (such as
Thawte or Verisign) along with anything else they might require:
http://www.verisign.com/ (http://www.verisign.com/)
http://www.thawte.com/ (http://www.thawte.com/)
5
If you are using a non-traditional CA (such as your own private Certificate Authority/Public
Key Infrastructure (CA/PKI), or if you are using a less well-known CA, you will need to import
the CA’s root certificates into the java cacerts file by entering the following command on the
command line of the Novell ZENworks Network Access Control server:
keytool -import -alias
<CA_alias>
-file
<ca_root_cert_file>
-keystore /usr/
local/nac/keystore/cacerts
Where:
<CA_alias>
is an alias unique to your cacerts file and preferably identifies the CA to which it
pertains
<ca_root_cert_file>
is the file containing the CA's root certificate
6
keytool
prompts for the password for the cacerts file, which should be the default:
changeit
.
7
If you are prompted, enter
yes
to trust the certificate.
8
Once you get your signed certificate back from the CA, import it into your keystore (see
Section 1.9, “Copying Files,” on page 28
), replacing the previously self-signed public
certificate for your key by entering the following command on the command line of the Novell
ZENworks Network Access Control server:
keytool -import -alias
<key_alias>
-trustcacerts -file
<signed_cert_file>
-
keystore /usr/local/nac/keystore/compliance.keystore
Where:
<key_alias>
is the name for the key within the keystore file
<signed_cert_file>
is the name of the file containing your CA-signed certificate
9
keytool
prompts for the password for the keystore_filename file, which is the password used
when the keystore was created.
10
Save and exit the file.
16.17 Moving an ES from One MS to Another
If you have an existing ES, you can move it to a different MS by performing the steps in this section.
To move an ES to a different MS:
Command line window
1
Log in to the ES as
root
using SSH or directly with a keyboard.
2
Enter the following command at the command line:
service nac-es stop
3
Log in the MS user interface that currently manages the ES you want to move.
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...