Managing the Certificate Database
Chapter
14
Managing CMS Keys and Certificates
481
By default, the Certificate Manager and Registration Manager use a single SSL
server certificate to do server-side authentication to all the CMS ports. If a
Certificate Manager is configured for SSL client authenticated communication with
the publishing directory, it also uses the SSL server certificate for authenticating to
the publishing directory. The Certificate Manager, if configured to function as a
trusted manager to a Data Recovery Manager, also uses its SSL server certificate for
SSL client authentication to the Data Recovery Manager. Depending on the
purpose for which the certificate being renewed is used currently, you should
configure the server appropriately.
•
To configure the server to use this certificate for authenticating to one of the
clients, see “Configuring the Server to Use Separate SSL Server Certificates” on
page 459.
•
To configure the Certificate Manager to use this certificate for authenticating to
the publishing directory, see “Step 5. Identify the Publishing Directory” on
page 636.
Step 5. Restart the Server
After you renew any of the CMS certificates using the wizard, you must restart the
server. For instructions, see “Restarting Certificate Management System” on
page 312.
Managing the Certificate Database
Each CMS instance has a certificate database, which is maintained in its internal
token. This database contains certificates belonging to the subsystems installed in
the CMS instance (see “Keys and Certificates for the Main Subsystems” on
page 420) and various CA certificates the subsystems use for validating the
certificates they receive.
Whether you use an internal token or an external token for generating and storing
key pairs, Certificate Management System always maintains its list of trusted and
untrusted CA certificates in its internal token.
You may need to add new certificates to the database, remove unwanted
certificates from the database, or change the trust settings of CA certificates in the
database. This section explains how to view the contents of the certificate database,
delete unwanted certificates, and change the trust settings of CA certificates
installed in the database using the CMS window. For information on adding
certificates to the database, see “Certificate Setup Wizard” on page 436.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...