Chapter 12. Editing Configuration in the CS.cfg File
288
NOTE
If the
password.conf
file is present, the subsystem assumes that
all
the required
passwords are present and properly formatted in clear text. If any passwords are missing
or wrongly formatted, then the system will not start.
For the CA, DRM, OCSP, and TKS subsystems, the expected passwords are:
•
internal
for the NSS database
•
internaldb
for the internal LDAP database
•
replicationdb
for the replication password
• any passwords to access external LDAP databases for publishing (CA only)
NOTE
If a publisher is configured after the
password.conf
file is removed, nothing is
written to the
password.conf
file. The server simply prompts for the new publishing
password the next time that the instance restarts.
• any external hardware token passwords
For the TPS, this prompts for three passwords:
•
internal
for the NSS database
•
tokendbpass
for the internal LDAP database
• any external hardware token passwords
All of the passwords which will be prompted for when the subsystem instance starts are listed in the
cms.passwordlist
in the
CS.cfg
file for the instance.
12.3.3.1. Configuring New Instances to Prompt for Passwords
To configure subsystem password prompts for a new CA, DRM, OCSP, or TKS instance, simply
remove the
password.conf
file in the
/var/lib/
subsystem_name
/conf
directory.
For the TPS:
1. Remove the
password.conf
file.
2. Edit the
nss.conf
file to change the
NSSPassPhraseDialog
from the password file to
builtin
.
...
original
...
NSSPassPhraseDialog defer:/var/lib/pki-tps/conf/password.conf
...
updates
...
# commenting out this line to enable password prompts
# NSSPassPhraseDialog defer:/var/lib/pki-tps/conf/password.conf
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...