Setting Up Privileged Users
Chapter
13
Managing Privileged Users and Groups
397
7.
Click Refresh to view the updated configuration.
Step 4. Check the Certificate Database for the CA Certificate
The CA that signed the agent’s SSL client certificate must be trusted by the
subsystem that services requests from the agent. Make sure that this CA’s
certificate exists in the subsystem’s certificate database (internal or external) and
that it is trusted. To check whether the CA’s certificate exists in your subsystem’s
certificate database, follow the instructions in “Viewing the Certificate Database
Content” on page 482.
•
If the CA certificate isn’t listed, follow the instructions in “Using the Wizard to
Install a Certificate or Certificate Chain” on page 452 and add the certificate to
the certificate database.
•
If the CA’s certificate is listed but untrusted, follow the instructions in
“Changing the Trust Settings of a CA Certificate” on page 485 and change the
trust setting to trusted.
Setting Up Trusted Managers
You can set up a Registration Manager or Certificate Manager to function as a
trusted manager to another CMS instance. This section explains how to do this.
•
Setting up Trusted Managers Using the Automated Process
•
Setting Up a Registration Manager as a Trusted Manager
•
Setting Up a Certificate Manager as a Trusted Manager
To understand the role of a trusted manager in your PKI, see “Trusted Managers”
on page 380.
Setting up Trusted Managers Using the Automated Process
Certificate Management System automates the process of setting up trusted
managers. The automated process is built into the request-approval form (the page
that displays the pending request) in the Agent Services interface and it enables the
person who has both Certificate Manager agent and Administrator privileges to create
new trusted managers for a CMS instance—that is, the Certificate Manager agent
who approves the subsystems’ certificate requests must belong to both the
Certificate Manager Agents and Administrators groups in the user and group
database of the Certificate Manager. For more information about these groups, see
“Groups and Their Privileges” on page 384.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...