Chapter 12. Editing Configuration in the CS.cfg File
278
There are two ports for enrolling security officers and the one URL to access the security officer
workstation UI:
• One enrollment UI over a standard port, http://server.example.com:7888
/cgi-bin/so/
enroll.cgi
• One enrollment UI over a secure (SSL) port, http://server.example.com:7889
/cgi-bin/so/
enroll.cgi
• One workstation UI, which is always over a secure (SSL) port, http://server.example.com:7888
/
cgi-bin/sow/welcome.cgi
Then there is one last URL which is accessed by operators, agents, and administrators over HTTPS,
https://server.example.com:7889/tus/
. This URL is used to manage the TPS subsystem,
such as configuring audit logging and adding users, and it also has minimal token management
operations, such as manually adding tokens to the TPS's token database.
As with the other subsystems, running
service pki-tps status
will show all of the ports and
interface URLs for the instance.
The Phone Home URL configured in the Enterprise Security Client's
esc-prefs.js
configuration file
determines which URL to access. Setting the Phone Home URL is described in the
Managing Smart
Cards with the Enterprise Security Client
guide.
12.1.7. Shared Certificate System Subsystem File Locations
There are some directories used by all Certificate System subsystems for general server operations,
listed in
Table 12.7, “Subsystem File Locations”
.
Directory Location
Contents
/var/lib/
subsystem_name
/var/lib64/
subsystem_name
Contains user-specific default and customized configuration files, profiles, certificate databases, web files, and other files for the subsystem instance.
/usr/share/java/pki
Contains Java archive files shared by the Certificate System subsystems. Along with shared files for all subsystems, there are subsystem-specific
files in subfolders:
pki/ca/ (CA)
pki/kra/ (DRM)
pki/ocsp/ (OCSP)
pki/tks/ (TKS)
Not used by the RA or TPS subsystems.
/usr/share/pki
Contains common files and templates used to create Certificate System instances. Along with shared files for all subsystems, there are subsystem-
specific files in subfolders:
pki/ca/ (CA)
pki/kra/ (DRM)
pki/ocsp/ (OCSP)
pki/ra/ (RA)
pki/tks/ (TKS)
pki/tps (TPS)
/usr/bin
Contains the
pkicreate
and
pkiremove
instance configuration scripts and tools (Java, native, and security) shared by the Certificate System
subsystems.
/var/lib/tomcat5/common/lib
Contains Java archive files shared by local Tomcat web applications and shared by the Certificate System subsystems.
Not used by the TPS and RA
subsystems.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...