Renewing Certificates for the Subsystems
478
Netscape Certificate Management System Installation and Setup Guide • March 2002
For all certificates, make sure the that CA-chain verification takes place smoothly.
For example, if you requested the certificate from a different CA, be sure to import
a CA certificate into the certificate database of the subsystem using the Certificate
Setup Wizard. For instructions, see “Using the Wizard to Install a Certificate or
Certificate Chain” on page 452. After you install the CA certificate, you can follow
the instructions in see “Changing the Trust Settings of a CA Certificate” on
page 485 to trust the CA certificate you imported.
Deploying Certificate Manager’s Renewed CA Signing Certificate
If you renewed a CA signing certificate, deploy it in the PKI environment that
depends on this certificate for validation. For example, you’ll need to add the
renewed CA certificate to the certificate databases of clients that trust this CA.
Similarly, if you have configured the Certificate Manager to publish CRLs to a
Online Certificate Status Manager, you will need to identify the Certificate
Manager to the Online Certificate Status Manager again. For details, see “Step 3.
Identify the CA to the OCSP Responder” on page 690.
You might also need to get a new agent certificate. For instructions, see the
procedure outlined in “Deploying Certificate Manager’s CA Signing Certificate”
on page 470.
Deploying Registration Manager’s Renewed Signing Certificate
Here’s what you must do:
1.
Install the renewed signing certificate in the subsystem’s certificate database.
Because the Registration Manager uses its signing certificate for SSL client
authentication to the subsystems, you must add the renewed signing certificate
to the internal database of all subsystems that have been configured to receive
requests from the Registration Manager.
To add the renewed certificate to a subsystem’s internal database:
a.
Note the instance ID and host name of the Registration Manager for which
you got the signing certificate; this information will help you to identify
the Registration Manager in a subsystem’s list of privileged users.
b.
Copy the renewed signing certificate, in its base-64 encoded format, to a
text file.
c.
Add the renewed certificate to the individual subsystem’s internal
database following the instructions in “Changing a Privileged User’s
Certificate” on page 414. Repeat this step for all subsystems that receive
requests from this Registration Manager.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...