
Installing an Online Certificate Status Manager
Chapter 5
OCSP Responder
171
e.
Click Next to continue.
If you closed the end-entity interface, you can get the CA certificate chain this way:
a.
Open a web browser window.
b.
Go to the end-entity URL for the Certificate Manager that issued the Online
Certificate Status Manager’s signing certificate.
c.
Select the Retrieval tab, and then choose Import CA Certificate Chain.
d.
Select the “Display the CA certificate chain in PKCS#7 for importing into a
server” option, and then click Submit.
e.
Copy the certificate chain to the clipboard.
f.
Return to the Installation Wizard.
g.
Paste the certificate chain into the text box.
h.
Click Next to continue.
17.
Key-Pair Information for SSL Server Certificate.
❍
Token.
Enter either
internal
(if you plan to use the internal/software token) or
the name of an external token to store the SSL server certificate and key pair. If
you have not previously initialized the token’s password, you must do so in this
screen. See “Tokens,” on page 164 for more information.
❍
Key Type.
Choose RSA .
❍
Key Length.
Available key sizes for RSA are 512, 768, 1024, 2048, 4096, or
Custom. Available key sizes for DSA are 512, 1024, or Custom (which must be in
increments of 64 bits only).
See “Signing Key Type and Length” on page 165 for more information.
Click Next to continue.
18.
Subject Name for SSL Server Certificate.
Type the values for the subject DN
components; these values identify the Online Certificate Status Manager’s SSL server
certificate. The CN must be the fully-qualified host name of the machine on which
you’re installing the Online Certificate Status Manager.
Click Next to continue.
19.
Certificate Extensions for SSL Server Certificate.
Select the required extensions.
The default settings should work for most deployments. If necessary, you can add an
additional extension by pasting its base-64 encoding in the space provided on this
screen.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...