Registration Manager Deployment Considerations
130
Red Hat Certificate System Administrator’s Guide • September 2005
When you get the certificates from a CS CA, you can set the Registration Manager up as a
trusted manager of the Certificate Manager by specifying this on the agent approval form
for the certificate request. Otherwise, you will need to manually set up the trusted
relationship.
About the Registration Manager’s Key Pairs and Certificates
This section describes the key pairs and certificates associated with the Registration
Manager.
Signing Key Pair and Certificate
Every Registration Manager you install has a certificate, identified as the
Registration
Manager signing certificate
,
whose public key corresponds to the private key the
Registration Manager uses to authenticate itself to the Certificate Manager. This certificate
is created and installed when you install the Registration Manager. The default nickname
for the certificate is
raSigningCert cert-<instance_id>
, where
<instance_id>
identifies the CS instance in which the Registration Manager is installed.
The Registration Manager’s signing certificate was issued by the CA to which you
submitted the certificate signing request.
If you configure the Registration Manager to function as a
trusted manager
to another
subsystem, the Registration Manager uses its signing certificate for SSL client
authentication to the subsystem; this is the default configuration.
SSL Server Key Pair and Certificate
Every Registration Manager you install has at least one
SSL server certificate
.
The first time
you generated this certificate is when you installed the Registration Manager. The default
nickname for the certificate is
Server-Cert cert-<instance_id>
, where
<instance_id>
identifies the CS
instance in which the Registration Manager is installed.
Registration Manager Interfaces
When you install a Registration Manager, three interfaces are enabled. The installation
wizard lets you choose the ports these interfaces listen on. The following interfaces, and
associated ports will be created:
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...