Keys and Certificates for the Main Subsystems
Chapter
14
Managing CMS Keys and Certificates
425
<token_name>
with the name of the token used for generating the key pair
and the certificate. If you used the internal/software token, use
Internal
Key Storage Token
as the value.
For example, your edited entries might look like this:
ca.crl_signing.cacertnickname=crlSigningCert cert-demoCA
ca.crl_signing.defaultSigningAlgorithm=MD5withRSA
ca.crl_signing.tokenname=Internal Key Storage Token
e.
Save your changes and close the file.
4.
Restart the Certificate Manager. Now the Certificate Manager is ready to use
the CRL signing certificate to sign the CRLs it generates.
SSL Server Key Pair and Certificate
Every Certificate Manager you have installed has at least one SSL server certificate.
The first time you generated this certificate is when you installed the Certificate
Manager. The default nickname for the certificate is
Server-Cert cert-<instance_id>
, where
<instance_id>
identifies the CMS
instance in which the Certificate Manager is installed.
The Certificate Manager’s SSL server certificate was issued by the CA to which you
submitted the certificate signing request. You might have submitted the request to
the Certificate Manager itself, another internally deployed CA, or a public CA. To
find out the issuer name, follow the instructions in “Viewing the Certificate
Database Content” on page 482.
The Certificate Manager uses its SSL server certificate to do SSL server-side
authentication to the following:
•
The End-Entity Services interface (the HTTPS port)
•
The Certificate Manager Agent Services interface
•
Clone Certificate Managers, when used as a master Certificate Manager in a
cloned CA setup (see “Cloning a Certificate Manager” on page 282)
By default, the Certificate Manager uses a single SSL server certificate for
authentication purposes. However, you can request and install additional SSL
server certificates for the Certificate Manager. For example, you can configure the
Certificate Manager to use separate server certificates for authenticating to the
End-Entity Services interface and Agent Services interface. For instructions, see
“Configuring the Server to Use Separate SSL Server Certificates” on page 459.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...