![Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Скачать руководство пользователя страница 277](http://html.mh-extra.com/html/red-hat/certificate-system-7-3-administration/certificate-system-7-3-administration_administration-manual_1427433277.webp)
Installing Certificates in the Certificate System Database
255
11.4.1.1. Installing Certificates through the Console
The Certificate Setup Wizard can install or import the following certificates into either an internal or
external token used by the Certificate System instance:
• Any of the certificates used by a Certificate System subsystem
• Any trusted CA certificates from external CAs or other Certificate System CAs
• Certificate chains
A certificate chain includes a collection of certificates: the subject certificate, the trusted root CA
certificate, and any intermediate CA certificates needed to link the subject certificate to the trusted
root. However, the certificate chain the wizard imports must include only CA certificates; none of the
certificates can be a user certificate.
In a certificate chain, each certificate in the chain is encoded as a separate DER-encoded object.
When the wizard imports a certificate chain, it imports these objects one after the other, all the way
up the chain to the last certificate, which may or may not be the root CA certificate. If any of the
certificates in the chain are already installed in the local certificate database, the wizard replaces the
existing certificates with the ones in the chain. If the chain includes intermediate CA certificates, the
wizard adds them to the certificate database as
untrusted
CA certificates.
The subsystem console uses the same wizard to install certificates and certificate chains. To install
certificates in the local security database, do the following:
1. Open the Console.
pkiconsole https://
hostname:SSLport
/ca
2. In the
Configuration
tab, select
System Keys and Certificates
from the left navigation tree.
3. There are two tabs where certificates can be installed, depending on the subsystem type and the
type of certificate.
• The
CA Certificates
tab is for installing CA certificates and certificate chains. For Certificate
Managers, this tab is used for third-party CA certificates or other Certificate System CA
certificates; all of the local CA certificates are installed in the
Local Certificates
tab. For all
other subsystems, all CA certificates and chains are installed through this tab.
• The
Local Certificates
tab is where all server certificates, subsystem certificates, and local
certificates such as OCSP signing or DRM transport are installed.
Select the appropriate tab.
4. To install a certificate in the
Local Certificates
tab, click
Add/Renew
. To install a certificate in the
CA Certificates
tab, click
Add
. Both will open the Certificate Setup Wizard.
a. When the wizard opens, select the
Install a certificate
radio button, and click
Next
.
b. Select the type of certificate to install. The options for the drop-down menu are the same
options available for creating a certificate, depending on the type of subsystem, with the
additional option to install a cross-pair certificate.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...