Getting New Certificates for the Subsystems
468
Netscape Certificate Management System Installation and Setup Guide • May 2002
•
You can get any number of SSL server certificates.
Decide on the CA that will sign the certificate
If you want to get a new self-signed CA certificate, you don’t have to make this
decision, because the CA itself signs it. For all other certificates, you must decide on
the CA that will sign the certificate.
If you want the certificate to be signed by an internally deployed CA, check to be
sure (for example, the policy configuration) that the CA can issue the certificate
you want request.
If you want the certificate to be signed by a public CA, find out the following:
•
Does the public CA have a public policy statement? If one is available, read it;
it may help you decide whether to request the certificate from this CA.
•
Is the public CA’s certificate already installed in the trusted CA in the trust
database of Certificate Management System? If not, do you want to install it?
•
Is the public CA a trusted CA in the trust database of Certificate Management
System? If not, do you want to trust it?
•
Can the public CA issue the certificate you want to request?
•
Does the public CA impose any restrictions on certificates it issues? For
example, if you are planning for requesting a subordinate CA certificate for a
Certificate Manager, you may want to find out whether the public CA imposes
any restrictions on the validity period, volume, or type of certificates your CA
can issue. If you are planning for requesting a signing certificate for a
Registration Manager, you may want to find out whether the public CA
imposes any restrictions on the validity period or the number of certificate
requests the Registration Manager can sign using the certificate. If you are
planning for requesting a transport certificate for a Data Recovery Manager,
you may want to find out whether the public CA imposes any restrictions on
the validity period or the number of keys the Data Recovery Manager can
archive using the certificate.
•
What information does the public CA expects you to provide with the
certificate request?
•
How long will the public CA take to deliver the certificate, and how will the
certificate be delivered to you? (The most common delivery mechanism is by
email.)
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...