Designing Your Novell eDirectory Network
85
no
vd
ocx
(e
n)
6 Ap
ril 20
07
The root administrator can also delegate the authority to use the Organizational CA by assigning the
following rights to subcontainer administrators. Subcontainer administrators require the following
rights to install Novell eDirectory SP2 with SSL security:
Read right to the NDSPKI:Private Key attribute on the Organizational CA’s object, located in
the Security container.
Supervisor right to the W0 object located in the Security container, inside the KAP object.
These rights are assigned to a group or a role, where all the administrative users are defined. For a
complete list of required rights to perform specific tasks associated with Novell Certificate Server,
refer to the
Novell Certificate Server (http://www.novell.com/documentation/beta/crt30/index.html)
online documentation.
2.7.2 Ensuring Secure eDirectory Operations on Linux, Solaris,
AIX, and HP-UX Systems
eDirectory includes Public Key Cryptography Services (PKCS), which contains the Novell
Certificate Server that provides Public Key Infrastructure (PKI) services, Novell International
Cryptographic Infrastructure (NICI), and SAS*-SSL server.
The following sections provide information about performing secure eDirectory operations:
“Verifying Whether NICI Is Installed and Initialized on the Server” on page 86
“Initializing the NICI Module on the Server” on page 86
“Starting the Certificate Server (PKI Services)” on page 87
“Stopping the Certificate Server (PKI Services)” on page 87
“Creating an Organizational Certificate Authority Object” on page 87
“Creating a Server Certificate Object” on page 87
“Exporting an Organizational CA's Self-Signed Certificate” on page 88
For information about using external certificate authority, refer to the
Novell Certificate Server
Administration Guide
(http://www.novell.com/documentation/beta/crt30/index.html)
.
Novell Certificate Server Task
Rights Required
Base security setup for installing the first server into
a new tree or upgrading the first server in a tree
where there is no base security previously installed
Supervisor right at the root of the tree
Supervisor right on the Security container
Base security setup for installing subsequent servers Supervisor right on the server’s container
Supervisor right on the W0 object (located
inside the Security container)
Creating the Organizational CA
Supervisor right on the Security container
Creating Server Certificate objects
Supervisor right on the server’s container
Read right to the NDSPKI:Private Key attribute
on the Organizational CA’s object
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...