Diagnostics
419
its operations. Before installing and configuring the clone, the master subsystem must be installed,
fully configured, and running.
A cloned subsystem is configured through standard configuration wizard. Before going through the
setup process, some manual preparation is required. To prepare for cloning, do the following:
•
If the keys and certificates are stored in the Internal Key Storage Token (software token).
When configuring the master instance, select
yes
in the
Export Keys and Certificates
panel to
back up the keys and certificates, and enter the password to protect the PKCS #12 file. Then restart
the master instance when configuration is complete.
If the keys and certificates were not backed up when the master instance was configured, they can
be backed up using the
pk12util
tool.
When configuring the clone instance, enter the location and the password for the PKCS #12 file in
the
Restore Keys and Certificates
screen. Then restart the clone instance when configuration is
complete.
•
If the keys and certificates are stored on a hardware token.
• Duplicate all the required keys and certificates, except the SSL server key and certificate to the
clone instance. Keep the nicknames for those certificates the same. Additionally, copy all the
necessary trusted root from the master instance to the clone instance.
• If the token is network-based, then the keys and certificates simply need to be available to the
token; the keys and certificates do not need to be copied.
• When using a network-based hardware token, make sure the high-availability feature is enabled
on the hardware token to avoid single point of failure.
19.2.1. Diagnostics
Use the
certutil
tool to list all the certificates in the clone instance to make sure that all the required
certificates are in place.
19.3. Testing the Cloned Configuration
To test the CA clone, do the following:
1. Request a certificate from the cloned CA.
2. Approve the request.
3. Download the certificate to the browser.
4. Revoke the certificate.
5. Check master CA's CRL for the revoked certificate. In the master Certificate Manager's agent
services page, click
Update Certificate Revocation List
. Find the CRL in the list.
The CRL should show the certificate revoked by the cloned Certificate Manager. If that certificate
is not listed, check logs to resolve the problem.
To test the OCSP clone, do the following:
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...