Editing the Configuration File
285
• The TPS and RA configure different token and certificate enrollment operations, respectively.
• The TKS lists profiles for deriving keys from different key types.
• The OCSP sets key information for different key sets.
12.2.3. Editing the Configuration File
WARNING
Do not edit the configuration file directly without being familiar with the configuration
parameters or without being sure that the changes are acceptable to the server. The
Certificate System fails to start if the configuration file is modified incorrectly. Incorrect
configuration can also result in data loss.
To modify the
CS.cfg
file:
1. Stop the subsystem instance.
service
subsystem_name
stop
The configuration file is stored in the cache when the instance is started. Any changes made to
the instance through the Console are changed in the cached version of the file. When the server
is stopped or restarted, the configuration file stored in the cache is written to disk. Stop the server
before editing the configuration file or the changes will be overwritten by the cached version when
the server is stopped.
2. Open the
/var/lib/
subsystem_name
/conf
directory.
3. Open the
CS.cfg
file in a text editor.
4. Edit the parameters in the file, and save the changes.
5. Start the subsystem instance.
service
subsystem_name
start
12.3. System Passwords
The Certificate System stores passwords used to bind to servers or to unlock tokens when the server
starts in a plain text file,
password.conf
.
Passwords for the internal database and other database-related passwords for optional features are
stored in a plain text file,
password.conf
, in the subsystem
conf/
directory. The passwords stored
within it are used to bind to the various Certificate System services. Since the
password.conf
file is
in clear text, it is possible to modify them simply through a text editor.
The list of passwords stored in this file includes the following:
• The bind password used by the Certificate System instance to access and update the internal
database.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...