Chapter 16. Managing Subsystem Certificates
392
NOTE
The public component of the storage key pair is not certified; there is no certificate that
corresponds to the public key. It is a self-signed certificate.
Keys encrypted with the storage key can be retrieved only by authorized key recovery agents.
16.1.4.3. SSL Server Certificate
Every Certificate System DRM has at least one SSL server certificate. The first SSL server certificate
is generated when the DRM is configured. The default nickname for the certificate is
Server-Cert
cert-
instance_id
, where
instance_id
identifies the DRM instance is installed.
The DRM's SSL server certificate was issued by the CA to which the certificate request was submitted,
which can be a Certificate System CA or a third-party CA. To view the issuer name, open the
certificate details in the
System Keys and Certificates
option in the DRM Console.
The DRM uses its SSL server certificate for server-side authentication to the DRM agent services
interface. By default, the Data Recovery Manager uses a single SSL server certificate for
authentication. However, additional SSL server certificates can be requested and installed for the
DRM.
16.1.4.4. Subsystem Certificate
Every member of the security domain is issued a server certificate to use for communications among
other domain members. The Data Recovery Manager is issued the subsystem certificate when the
instance is first configured, as with its SSL certificate.
The default nickname for the certificate is
subsystemCert cert-
instance_id
.
16.1.4.5. Audit Log Signing Key Pair and Certificate
The DRM keeps a secure audit log of all events which occurred on the server. To guarantee that the
audit log has not been tampered with, the log file is signed by a special log signing certificate.
The audit log signing certificate is issued when the server is first configured.
16.1.5. TKS Certificates
The TKS has three certificates. The SSL server and subsystem certificates are used for standard
operations. An additional signing certificate is used to protect audit logs.
•
Section 16.1.5.1, “SSL Server Certificate”
•
Section 16.1.5.2, “Subsystem Certificate”
•
Section 16.1.5.3, “Audit Log Signing Key Pair and Certificate”
16.1.5.1. SSL Server Certificate
Every Certificate System TKS has at least one SSL server certificate. The first SSL server certificate
is generated when the TKS is configured. The default nickname for the certificate is
Server-Cert
cert-
instance_id
.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...