System Architecture
Chapter 1
Overview
61
•
FIPS 140-1 module. This module complies with the FIPS 140-1 government standard
for implementations of cryptographic modules. Many products sold to the US
government must comply with one or more of the FIPS standards. The FIPS 140-1
module includes a single, built-in FIPS 140-1 Certificate DB token (as shown in Figure
1-5 on page 56), which handles both cryptographic operations and communication with
the certX.db and keyX.db files.
Any PKCS #11 module can be used with CS. The server uses a file called secmod.db to
keep track of the modules that are available. You can modify this file using the
modutil
tool, which is explained in the following documentation:
http://www.mozilla.org/projects/security/pki/nss/tools/
For example, you need to modify secmod.db if you are installing hardware accelerators for
use in signing operations.
Management Tools
Command line tools are provided by CS for occasional management of the CS system:
•
backup/restore tool
•
password cache tool
•
audit log signature verification tool
•
enrollment pin generation tool
•
mass revocation tool
•
(signed) CS request tool
•
bulk certificate issuance tool
JRE
JRE (Java Runtime Environment) provides the Java Virtual Machine (JVM) and supporting
class libraries needed to run CS.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...