Detecting Tokens
415
16.7.1. Detecting Tokens
To see if a token can be detected by Certificate System to be installed or configured, use the
TokenInfo
utility.
TokenInfo /var/lib/pki-ca/alias
Database Path: /var/lib/pki-ca/alias
Found external module 'NSS Internal PKCS #11 Module'
This utility will return all tokens which can be detected by the Certificate System, not only tokens which
are installed in the Certificate System.
16.7.2. Viewing Tokens
To view a list of the tokens currently installed for a Certificate System instance, use the
modutil
utility.
1. Open the instance
alias
directory. For example:
cd /var/lib/pki-ca/alias
2. Show the information about the installed PKCS #11 modules installed as well as information on
the corresponding tokens using the
modutil
tool.
modutil -dbdir . -nocertdb -list
16.7.3. Changing a Token's Password
The token, internal or external, that stores the key pairs and certificates for the subsystems is
protected (encrypted) by a password. To decrypt the key pairs or to gain access to them, enter the
token password. This password is set when the token is first accessed, usually during Certificate
System installation.
It is good security practice to change the password that protects the server's keys and certificates
periodically. Changing the password minimizes the risk of someone finding out the password. To
change a token's password, use the
certutil
command-line utility.
For information about
certutil
, see
http://www.mozilla.org/projects/security/pki/nss/tools/
.
The single sign-on password cache stores token passwords in the
password.conf
file. This file must
be manually updated every time the token password is changed. For more information on managing
passwords through the
password.conf
file, see
Section 12.3, “System Passwords”
.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...