Chapter 2. Prerequisites Before Installing Certificate System
16
Information
Description
default Directory Manager DN is
cn=Directory
Manager
.
Certificate and key recovery files (for cloning)
If the subsystem being configured is a clone of
another subsystem, then the backup files for the
master subsystem must be locally accessible.
Table 2.2. Required Information for Configuring Subsystems
2.5. Setting up Tokens for Storing Certificate System
Subsystem Keys and Certificates
A subsystem instance generates and stores its key information in a key store, called a
token
. A
subsystem instance can be configured for the keys to be generated and stored using the internal NSS
token or on a separate cryptographic device, a hardware token.
2.5.1. Types of Hardware Tokens
A
token
is a hardware or software device that performs cryptographic functions and stores public-key
certificates, cryptographic keys, and other data.
The Certificate System defines two types of tokens,
internal
and
external
, for storing key pairs and
certificates that belong to the Certificate System subsystems.
2.5.1.1. Internal Tokens
An internal (software) token is a pair of files, usually called the
certificate database
and
key database
,
that the Certificate System uses to generate and store its key pairs and certificates. The Certificate
System automatically generates these files in the filesystem of its host machine when first using the
internal token. These files were created during the Certificate System subsystem configuration if the
internal token was selected for key-pair generation.
In the Certificate System, the certificate database is named
cert8.db
; the key database is named
key3.db
. These files are located in the
instanceID
/alias
directory.
2.5.1.2. External Tokens
An external token refers to an external hardware device, such as a smart card or hardware security
module (HSM), that the Certificate System uses to generate and store its key pairs and certificates.
The Certificate System supports any hardware tokens that are compliant with PKCS #11.
PKCS #11 is a standard set of APIs and shared libraries which isolate an application from the details
of the cryptographic device. This enables the application to provide a unified interface for PKCS #11-
compliant cryptographic devices.
The PKCS #11 module implemented in the Certificate System supports cryptographic devices supplied
by many different manufacturers. This module allows the Certificate System to plug in shared libraries
supplied by manufacturers of external encryption devices and use them for generating and storing
keys and certificates for the Certificate System managers.
Consider using external tokens for generating and storing the key pairs and certificates used by
Certificate System. These devices are another security measure to safeguard private keys because
hardware tokens are sometimes considered more secure than software tokens.
Содержание CERTIFICATE SYSTEM 8 - DEPLOYMENT
Страница 5: ...v 9 5 7 Shared Certificate System Subsystem File Locations 119 Index 121 ...
Страница 6: ...vi ...
Страница 18: ...8 ...
Страница 32: ...22 ...
Страница 50: ...Chapter 3 Installation and Configuration 40 9 Optionally change the subject names for the certificates ...
Страница 70: ...60 ...
Страница 104: ...94 ...
Страница 114: ...104 ...
Страница 118: ...108 ...
Страница 132: ...122 ...