
Configuring the Certificate Manager
Chapter 3
Certificate Manager
107
If you configure the Certificate Manager to function as a
trusted manager
to a Data
Recovery Manager, the Certificate Manager also uses its SSL server certificate for SSL
client authentication to the Data Recovery Manager. For details on trusted managers, see
“Trusted Managers” on page 317. You can also configure the Certificate Manager to use an
alternate certificate for this purpose; see “Getting an SSL Client Certificate for a
Subsystem” on page 311.
CA Certificate Renewal or Reissuance
When a CA signing certificate expires, all certificates signed with the CA’s corresponding
signing key become invalid. End entities use information in the CA certificate to verify the
certificate’s authenticity. If the CA certificate itself has expired, applications cannot chain
the certificate to a trusted CA.
There are two ways of dealing with CA certificate expiration:
•
Renewing a CA certificate
involves issuing a new CA certificate with the same
subject name and public and private key material as the old CA certificate, but with an
extended validity period. As long as the new CA certificate is distributed to all users
well before the old CA certificate expires, this approach allows certificates issued
under the old CA certificate to continue working for the full duration of their validity
periods.
•
Reissuing a CA certificate
involves issuing a new CA certificate with a new name,
public and private key material, and validity period. This approach avoids some of the
problems associated with renewing a CA certificate, but it requires more work for both
administrators and users to implement. All certificates issued by the old CA, including
those that have not yet expired, must be renewed by the new CA.
There are advantages and disadvantages to each approach. Correct use of extensions, for
example the
authorityKeyIdentifier
extension, can also affect the transition from an
old CA certificate to a new one. You should begin planning for CA renewal or reissuance
before you install any CS managers; consider any ramifications your planned procedures
may have for extensions, policies, and other aspects of your initial PKI deployment.
Changing Ports and IP Addresses
You set up the ports for each of the interfaces when you install the Certificate Manager.
You can change the ports that any of the interfaces listen on, and you can remove the HTTP
(non-SSL) end-entity port if you will not use it. For information on changing ports, see
“Ports,” on page 275. For information about the ports that are setup with a Certificate
Manager, see “Certificate Manager Interfaces,” on page 83.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...