Configuring the Server’s Security Preferences
462
Netscape Certificate Management System Installation and Setup Guide • March 2002
6.
Once you have the certificate request ready, submit it to a CA so that it can
issue a certificate. For general instructions to use the wizard to request a
certificate, see section “Using the Wizard to Request a Certificate” on page 437.
7.
If you submitted the request to a Certificate Manager and if you have agent
privileges for that Certificate Manager, log in to its Agent Services interface,
locate the request, and check the request for required extensions. (If you
submitted the request to any other CA, you must ask the person managing that
CA to make the same changes to the request before approving it.)
Make sure that only the
SSL Client
option for certificate type is selected in the
request. For certificates with no Netscape Certificate Type extensions, the Key
Usage extension must be included with
Signing
and
Encryption
bits set.
8.
Approve the request.
9.
Once you have the certificate ready, restart the wizard and install the certificate
in the Certificate Manager’s database. For general instructions to use the
wizard to add a certificate, see “Using the Wizard to Install a Certificate or
Certificate Chain” on page 452.
Note that the default nickname for the certificate is
crlSigningCert cert-<instance_id>
, where
<instance_id>
identifies the
CMS instance in which the Certificate Manager is installed.
10.
After you’ve installed the certificate successfully, go to the Tasks tab and stop
the Certificate Manager.
11.
Configure the Certificate Manager to use this certificate.
After you install the certificate, configure the Certificate Manager to use the
new certificate for SSL client authentication to the publishing directory. For
instructions, see “Step 5. Identify the Publishing Directory” on page 636.
Setting Up Cipher Preferences for SSL
Communications
A cipher is the algorithm used in encryption. Some ciphers have stronger encryption
capabilities than others. Generally speaking, the more bits a cipher uses during
encryption, the harder it is to decrypt the data.
When a client initiates an SSL connection with Certificate Management System, it
lets the server know what ciphers it prefers to use to encrypt information. In any
two-way encryption process, both parties must use the same ciphers. A number of
ciphers are available; your server needs to be able to use the most popular ones.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...