Chapter 3. Administrative Basics
106
3.12.3. Restricting Access to the Internal Database
The Red Hat Directory Server Console displays an entry or icon for the Directory Server instance that
the Certificate System uses as its internal database.
Unlike the Certificate System Console, in which access is restricted to users with Certificate System
administrator privileges, the Directory Server Console can be accessed by any user. The user can
open the Directory Server Console for the internal database and change to the data stored there,
such as deleting users from the Certificate System administrators group or adding his own entry to the
group.
Access can be restricted to the internal database to only those users who know the Directory Manager
DN and password. This password can be changed by modifying the single sign-on password cache.
1. Log into the Directory Server Console.
2. Select the Certificate System internal database entry, and click
Open
.
3. Select the
Configuration
tab.
4. In the navigation tree, expand
Plug-ins
, and select
Pass-Through Authentication
.
5. In the right pane, deselect the
Enable plugin
checkbox.
6. Click
Save
.
The server prompts to restart the server.
7. Click the
Tasks
tab, and click
Restart the Directory Server
.
8. Close the Directory Server Console.
9. When the server is restarted, open the Directory Server Console for the internal database
instance.
The
Login to Directory
dialog box appears; the
Distinguished Name
field displays the Directory
Manager DN; enter the password.
The Directory Server Console for the internal database opens only if the correct password is
entered.
3.13. Backing up and Restoring Certificate System
Backup and restore tools are no longer included with the Certificate System. However, the Certificate
System components can still be archived and restored manually, and this can be necessary for
deployments where information cannot be accessed if certificate or key information is lost. There are
three major parts of the Certificate System which need backed up routinely in case of data loss or
hardware failure:
•
Internal database.
The Directory Server provides its own back up scripts and procedures; see the
Directory Server documentation for more information on backing up the LDAP database.
•
Security databases.
The security databases store the certificate and key material. If these are stored
on an HSM, then consult the HSM vendor documentation for information on how to back up the
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...