data:image/s3,"s3://crabby-images/00e95/00e95a42ba57be7af948b64bdcd2e16f3fd32597" alt="Red Hat CERTIFICATE 7.1 ADMINISTRATOR Скачать руководство пользователя страница 222"
Configuring Key Archival and Recovery Process
222
Red Hat Certificate System Administrator’s Guide • September 2005
b.
Use the command-line tool called
certutil
to retrieve the transport certificate
from the Data Recovery Manager’s certificate database. (For information on the
certutil
tool, check this site:
http://www.mozilla.org/projects/security/pki/nss/tools/
First, go to this directory:
<server_root>/cert-<instance_id>/config
Next, run this command:
<server_root>/bin/cert/tools/certutil -L
-d . -n kraTransportCert cert-<instance_id> -a
The transport certificate appears. View the certificate information. Make sure that
the certificate you are looking at is the correct one; the certificate shows the DN
that was specified for the transport certificate during the installation of Data
Recovery Manager.
c.
Copy the base-64 encoded certificate,
excluding
the marker lines
-----BEGIN
CERTIFICATE-----
and
-----END CERTIFICATE-----
, to a text file. The
copied information should look like the example below:
MIICDjCCAXegAwIBAgICAfMwDQYJKoZIhvcNAQEEBQAwdzELMAkGA1UEBhMCV
VMxLDAqBgNVBAoTI0
5ldHNjYXBlIENvbW11bmljYXRpb25zIENvcnBvcmF0aW9uMREwDwYDVQQLEwh
IYXJkY29yZTEnMCUG
A1UEAxMeSGFyZGNvcmUgQ2VydGlmaWNhdGUgU2VydmVyIElJMB4XDTk4MTExO
TIzNDIxOVoXDTk5MD
UxODIzNDIxOVowLjELMAkGA1UEBhMCVVMxETAPBgNVBAoTCG5ldHNjYXBlMQw
wCgYDVQQDEwNLUmEw
XDANBgkqhkiG9w0BAQEFAANLADBIAkEArrbDiYUI5SCdlCKKa0bEBn1m83kX6
bdhytRYNkdHB95B
2.
Update the JavaScript method in the enrollment form.
To do this:
a.
Go to the host system of the enrollment authority and locate the user-enrollment
form. The default forms are at these locations:
<server_root>/cert-<instance_id>/web-apps/ee ca
and
<server_root>/cert-<instance_id>/web-apps/ee/ra
b.
Open the enrollment form (ProfileSelect.template) that you want to use in a text
editor.
c.
In the form, locate the
generateCRMFRequest()
JavaScript method.
d.
Add a variable for the transport certificate.
Below the commented text, add this line:
var kraTransportCert =
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...