Archiving of Rotated Log Files
770
Netscape Certificate Management System Installation and Setup Guide • May 2002
Certificate Management System does, however, provide a command-line utility,
called
signtool
, that allows you to sign log files before archiving them. This gives
you a means of tamper detection. For details, see “Signing Log Files” on page 770.
Signing Log Files
Certificate Management System allows you to digitally sign log files before you
archive them or distribute them for audit purposes. This feature enables you to
check whether the log files have been tampered with since being signed.
For signing log files, you use a command-line utility called Netscape Signing Tool
(
signtool
). For details about this utility, check this site:
http://www.mozilla.org/projects/security/pki/nss/tools/
The utility uses information in the certificate (
cert7.db
), key (
key3.db
), and
security module (
secmod.db
) databases of Certificate Management System.
Before you begin signing the log files, follow these guidelines:
•
Determine the key pair you want to use for signing the log directory. Typically,
you should use the Certificate Manager’s (the CA’s) signing key pair. Also find
out the nickname of the certificate that corresponds to this key pair.
•
If you have deployed many CAs, locate the CMS instance in which the CA you
want to use is installed.
•
Find out whether the key pair is in an internal or external token. If it is in an
external token, make sure the token is currently installed. You will also need to
know the password for the token.
•
Determine which log files need to be signed. Put all the files that need to be
signed in one or more directories. (The utility can sign a directory containing
files; it cannot sign individual files.) Make sure these directories are in the host
machine in which the CA is installed.
•
Determine names for the output files; the output you receive will be a JAR file
(which is a signed zip file). You may want to give names that will help you
identify these JAR files easily in the future.
When you are ready with all this information, follow the procedure below to sign
the log directories:
1.
Go to the CMS instance in which the CA whose key pair you want to use for
signing is installed.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...