Chapter 16. Managing Subsystem Certificates
390
subsystem certificates are made. These certificate requests are submitted to a CA (either a Certificate
System CA or a third-party CA) and must be installed in the Online Certificate Status Manager
database to complete the configuration process.
•
Section 16.1.3.2, “SSL Server Key Pair and Certificate”
•
Section 16.1.3.3, “Subsystem Certificate”
•
Section 16.1.3.4, “Audit Log Signing Key Pair and Certificate”
•
Section 16.1.3.5, “Recognizing Online Certificate Status Manager Certificates”
16.1.3.1. OCSP Signing Key Pair and Certificate
Every Online Certificate Status Manager has a certificate, the OCSP signing certificate, which has
a public key corresponding to the private key the Online Certificate Status Manager uses to sign
OCSP responses. The Online Certificate Status Manager's signature provides persistent proof
that the Online Certificate Status Manager has processed the request. This certificate is generated
when the Online Certificate Status Manager is configured. The default nickname for the certificate is
ocspSigningCert cert-
instance_ID
, where
instance_ID
is the Online Certificate Status Manager
instance name.
16.1.3.2. SSL Server Key Pair and Certificate
Every Online Certificate Status Manager has at least one SSL server certificate which was generated
when the Online Certificate Status Manager was configured. The default nickname for the certificate
is
Server-Cert cert-
instance_ID
, where
instance_ID
identifies the Online Certificate Status
Manager instance name.
The Online Certificate Status Manager uses its server certificate for server-side authentication for the
Online Certificate Status Manager agent services page.
The Online Certificate Status Manager uses a single server certificate for authentication purposes.
Additional server certificates can be installed and used for different purposes.
16.1.3.3. Subsystem Certificate
Every member of the security domain is issued a server certificate to use for communications among
other domain members. The Online Certificate Status Manager is issued the subsystem certificate
when the instance is first configured, as with its SSL certificate.
The default nickname for the certificate is
subsystemCert cert-
instance_id
.
16.1.3.4. Audit Log Signing Key Pair and Certificate
The OCSP keeps a secure audit log of all events which occurred on the server. To guarantee that the
audit log has not been tampered with, the log file is signed by a special log signing certificate.
The audit log signing certificate is issued when the server is first configured.
16.1.3.5. Recognizing Online Certificate Status Manager Certificates
Depending on the CA which signed the Online Certificate Status Manager's SSL server certificate, it
may be necessary to get the certificate and issuing CA recognized by the Certificate Manager.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...