Keys and Certificates for the Main Subsystems
424
Netscape Certificate Management System Installation and Setup Guide • May 2002
f.
Once you have the certificate request ready, submit it to the Certificate
Manager so that it can issue a certificate—in the request submission screen
of the wizard, use the auto-submission feature by entering the Certificate
Manager’s hostname and port number so that the request gets added to the
Certificate Manager’s agent queue. For general instructions to use the
wizard to request a certificate, see section “Using the Wizard to Request a
Certificate” on page 437.
g.
Log in to the Agent Services interface, check the request for required
extensions. For example, the CRL signing certificate must contain the Key
Usage extension with the
crlSigning
bit set. (By default, the Certificate
Manager’s policy is configured to add the Key Usage extension with
correct bits to the CRL signing certificate; see the policy rule named
CRLSignCertKeyUsageExt
, which is an instance of
KeyUsageExt
plug-in.)
h.
Approve the request.
i.
Once you have the CRL signing certificate ready, restart the wizard and
install the certificate in the Certificate Manager’s database. For general
instructions to use the wizard to add a certificate, see “Using the Wizard to
Install a Certificate or Certificate Chain” on page 452.
2.
After you’ve installed the certificate successfully, go to the Tasks tab and stop
the Certificate Manager.
3.
Update the Certificate Manager’s configuration to recognize the new key pair
and certificate.
a.
In the Certificate Manager host machine, go to this directory:
<server_root>/cert-<instance_id>/config
b.
Open the configuration file (
CMS.cfg
) in a text editor.
c.
Add the following lines to the configuration file:
ca.crl_signing.cacertnickname=<nickname> cert-<instance_id>
ca.crl_signing.defaultSigningAlgorithm=<signing_algorithm>
ca.crl_signing.tokenname=<token_name>
d.
Edit the lines as below. Replace
<nickname>
with the name assigned to the CRL signing certificate.
<instance_id>
with the name assigned to the Certificate Manager
instance.
<signing_algorithm>
with
MD5withRSA
,
MD2withRSA
, or
SHA1withRSA
, if
the key type is RSA, or
SHA1withDSA
, if the key type is DSA.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...