Renewing Certificates for the Subsystems
Chapter
14
Managing CMS Keys and Certificates
477
The wizard also deletes the old certificate from the server’s certificate database and
adds the renewed certificate to the database, so that the server is able to use the
renewed certificate upon restart. This feature restricts you to set the value of the
notBefore
attribute of the renewed certificate to either the current time or any time
in the past, but not in the future.
If you set the validity period of the renewed certificate to begin on a future date
and time, the server fails to use the certificate for its intended purposes. If this
happens, you may either reinstall the old certificate (saved to the text file
mentioned above) or renew the certificate again with an appropriate validity
period.
Step 3. Install the Renewed Certificate
When you receive the renewed certificate from the CA, you must install it in the
token that contains the key pair for the certificate; this is the token you used to
generate the request in Step 2.
The Certificate Setup Wizard automates the process of installing certificates used
by the CMS managers. For instructions on using the wizard, see “Using the Wizard
to Install a Certificate or Certificate Chain” on page 452.
Step 4. Deploy the Renewed Certificate
Follow the instructions appropriate for the certificate you installed:
•
If you installed a renewed CA signing certificate for a Certificate Manager, see
section “Deploying Certificate Manager’s Renewed CA Signing Certificate” on
page 478.
•
If you installed a renewed signing certificate for a Registration Manager, see
section “Deploying Registration Manager’s Renewed Signing Certificate” on
page 478.
•
If you installed a renewed transport certificate for a Data Recovery Manager,
see section “Deploying Data Recovery Manager’s Renewed Transport
Certificate” on page 479.
•
If you installed a renewed SSL server certificate, see section “Deploying a
Subsystem’s Renewed SSL Server Certificate” on page 480.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...