Keys and Certificates for the Main Subsystems
Chapter
14
Managing CMS Keys and Certificates
423
CRL Signing Key Pair and Certificate
By default, a Certificate Manager you have installed uses the same key pair, the one
that corresponds to the CA signing certificate explained in “CA Signing Key Pair and
Certificate” on page 421, for signing certificates and certificate revocation lists
(CRLs). For details about CRLs, see “What’s a CRL?” on page 591.
If you want a Certificate Manager to use a separate key pair for signing the CRL it
generates, you can do so after installation. The instructions are provided below.
Note that a Certificate Manager’s CRL signing certificate must be signed or issued
by itself; make sure you submit the request to the Certificate Manager itself.
1.
Request and install a CRL signing certificate for the Certificate Manager. To do
this, you may use either of these options:
❍
Use the Certificate Setup Wizard available within the CMS window.
❍
Use the Certificate Database tool (
certutil
) to generate a key pair, request
a certificate for the key pair, and install the certificate in the Certificate
Manager’s certificate database. For more information about the Certificate
Database tool, check this site:
http://www.mozilla.org/projects/security/pki/nss/tools/
To request and install a CRL signing certificate for a Certificate Manager using
its Certificate Setup Wizard, follow these instructions:
a.
Log in to Netscape Console; see “Logging In to Netscape Console” on
page 326.
b.
Locate the CMS instance for the Certificate Manager, make sure it’s started,
and then log in to the CMS window of the Certificate Manager.
c.
Select the Configuration tab, and then select the Encryption tab.
d.
Click the Certificate Setup Wizard button to launch the wizard, which is
explained in “Certificate Setup Wizard” on page 436.
e.
Select the option to request a certificate and then follow the on-screen
prompts to generate a certificate request for the CRL signing certificate—in
the Certificate Selection window, select
Other
and specify
caCrlSigning
as the certificate type in the associated text field.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...