Tokens for Storing CMS Keys and Certificates
Chapter
14
Managing CMS Keys and Certificates
431
Tokens for Storing CMS Keys and Certificates
A token is a hardware or software device that performs cryptographic functions
and optionally stores public-key certificates, cryptographic keys, and data defined
by the application using the cryptographic services. Alternatively, a token can also
be considered as a device that you can use to generate and store your key pairs and
corresponding certificates.
Certificate Management System defines two types of tokens, internal and external,
for storing key pairs and certificates that belong to the Certificate Manager,
Registration Manager, Data Recovery Manager, and Online Certificate Status
Manager.
Internal Token
An internal (software) token refers to a pair of software files, usually called
certificate database and key database, that Certificate Management System uses to
generate and store its key pairs and certificates. Certificate Management System
automatically generates these files in the file system of its host machine when you
choose to use the internal token for the first time. These files were created for you
during CMS installation if you chose to use the internal token for key-pair
generation.
In the CMS host system, the certificate database is identified by the name
cert-<instance_id>-<machine_name>-cert7.db
; the key database is identified
by the name
cert-<instance_id>-<machine_name>-key3.db
. You can find both
these files in the
<server_root>/alias
directory.
External Token
An external (hardware) token refers to an external hardware device, such as a
smart card, FORTEZZA card, or other crypto card, that Certificate Management
System uses to generate and store its key pairs and certificates. Certificate
Management System supports any hardware tokens that are compliant with
PKCS#11 version 2.01. For details, see the information provided at this URL:
NOTE
Only those who have the password that protects a token can access
it. For information on changing this password, use the
certutil
tool. The documentation for the tool can be found here:
http://www.mozilla.org/projects/security/pki/nss/tools/
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...