Requesting Certificates
243
F0aW9uczngjhnMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTk4MDgyNzE5MDAwMFoXDTk5MDIyMzE5MDA
wMnbjdgngYoxIDAeBgNVBAoTF05ldHNjYXBlIENvbW11bmljYXRpb25zMQ8wDQYDVQQLEwZQZW9wbGUxFz
AVBgoJkiaJkIsZAEBEwdzdXByaXlhMRcwFQYDVQQDEw5TdXByaXlhIFNoZXR0eTEjMCEGCSqGSIb3Dbndg
JARYUc3Vwcml5Yhvfggsvwryw4y7214vAOBgNVHQ8BAf8EBAMCBLAwFAYJYIZIAYb4QgEBAQHBAQDAgCAM
A0GCSqGSIb3DQEBBAUAA4GBAFi9Fkzsue0kTXawbwamGdYql2wjWeLmD4CP4x
-----END NEW CERTIFICATE REQUEST-----
The wizard also copies the certificate request to a text file it creates in the configuration directory,
which is located at
/var/lib/
instance_id
/conf/
. The name of the text file depends on the type
of certificate requested. The possible text files are listed in
Table 11.2, “Files Created for Certificate
Signing Requests”
.
Filename
Certificate Signing Request
cacsr.txt
CA signing certificate
ocspcsr.txt
Certificate Manager OCSP signing certificate
kracsr.txt
DRM transport certificate
ocspcsr.txt
OCSP signing certificate
sslcsr.txt
SSL server certificate
othercsr.txt
Other certificates, such as Certificate Manager
CRL signing certificate or SSL client certificate
Table 11.2. Files Created for Certificate Signing Requests
Do not modify the certificate request before sending it to the CA. The request can either be
submitted automatically through the wizard or copied to the clipboard and manually submitted to
the CA through its end-entities page.
NOTE
The wizard's auto-submission feature can submit requests to a remote Certificate
Manager only. It cannot be used for submitting the request to a third-party CA.
14. Submit the certificate request to a CA.
• Submit the request to a remote Certificate System CA through the wizard. See
Section 11.2.2.1,
“Submitting Certificate Requests through the Console”
.
• Copy the request to the clipboard to submit the request through the CA enrollment forms. See
Section 11.2.2.2, “Submitting Certificate Requests through the End-Entities Page”
.
• Submit the request to a third-party CA. See
Section 11.2.2.3, “Submitting a Certificate Request
to a Third-Party CA”
.
NOTE
Requests created through a Certificate Manager Console are automatically submitted
to the CA without this step.
11.2.1.3. Requesting Certificates Using certutil
To request subsystem certificates using the
certutil
utility, do the following:
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...