Managing the Certificate Database
Chapter
14
Managing CMS Keys and Certificates
485
Changing the Trust Settings of a CA Certificate
Certificate Management System relies on the CA certificates in its certificate
database for validating certificates it receives during an SSL-enabled
communication. For example, when a Certificate Manager is authenticating a
Registration Manager that has sent a certificate signing request, the Certificate
Manager checks its certificate database to see whether the CA that has signed the
certificate presented by the Registration Manager is included in the database as a
trusted CA.
You may need to change the status of a currently trusted CA to untrusted (or vice
versa) temporarily or permanently. For example, you may be notified that a CA is
experiencing technical difficulty that prevents certificate authentication. By making
the CA certificate untrusted, you can prevent entities whose certificates have been
signed by that CA from successfully authenticating to Certificate Management
System. You can then return the trust option to trusted when the CA notifies you
that the problem has been resolved.
If you want to untrust a CA permanently, you should consider removing its
certificate from the trust database altogether. For instructions, see “Deleting a
Certificate From the Certificate Database” on page 484.
Changing the trust setting changes the trust flag (or bit) in the CA certificate. To
change the trust setting of a CA certificate:
1.
Log in to the CMS window (see “Logging In to the CMS Window” on
page 333).
2.
Select the Configuration tab, and then in the right pane, select the Encryption
tab.
3.
Click Manage Certificate.
The Certificate Database Management window appears.
The window lists the certificates currently installed for the selected CMS
instance; the list is a table, with each certificate occupying a row.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...