Configuring the Server’s Security Preferences
310
Red Hat Certificate System Administrator’s Guide • September 2005
•
The version of SSL that an instance of CS must use during SSL communication. The
latest version is SSL version 3, but many older clients use SSL version 2. Because
client authentication is required for performing privileged operations, you must enable
SSL version 3 ciphers supported by CS. For details, see “Configuring the Server’s
Security Preferences,” on page 309.
Configuring the Server to Use Separate SSL Server
Certificates
You can configure a CS instance to use separate SSL server certificates for authenticating to
Red Hat Console, the Agent Services interface, and the end entity services interface.
This configuration involves the following steps:
•
Step 1. Get the Required SSL Server Certificates
•
Step 2: Update the Configuration
Step 1. Get the Required SSL Server Certificates
You must first request and install the required number of SSL server certificates for the
particular CS instance. For instructions, see “Consideration When Getting New Certificates
for the Subsystems” on page 303.
Once you have installed the certificates, you should be able to see them in the list of SSL
server certificates in the Encryption tab of the CS window.
Step 2: Update the Configuration
After you verify that the certificates are installed, configure the server as follows:
1.
Stop the CS instance; see “Starting, Stopping, and Restarting CS Instances” on
page 246.
2.
Go to this directory:
<server_root>/cert-<instance_id>/config
3.
In a text editor, open the
server.xml
file.
4.
Locate the
servercertnickname
parameter for the interface of your interest.
❍
To change the certificate used for authenticating to the Agent Services interface,
edit the value assigned to the
servercertnickname
parameter in the
id="agent"
section.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...