Novell OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010 Implementation Manual page 229

Planning and implementation guide
Hide thumbs Also See for OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010:
Table of Contents

Advertisement

Location
/etc/opt/novell/certs
Novell Certificate Server
The component that generates eDirectory keys and certificates is the Novell Certificate Server.
This certificate server provides public key cryptography services that are natively integrated into
Novell eDirectory. You use the server to can mint, issue, and manage both user and server
certificates to protect confidential data transmissions over public communications channels such as
the Internet.
For complete information on the Novell Certificate Server, see the
Administration
Guide.
Server Self-Provisioning
When activated, Server Self-Provisioning lets server objects in eDirectory create their own
certificates. You must activate this option if you want PKI Health Check to automatically maintain
your server certificates.
For more information on this feature, see
Certificate Server 3.3.4 Administration
PKI Health Check
The PKI health check runs whenever the certificate server starts.
If you have enabled Server Self-Provisioning, the health check routine automatically replaces server
certificates when any of the following are detected:
The certificates don't exist.
The certificates have expired.
The certificates are about to expire.
The IP or DNS information on the certificates doesn't match the server configuration.
The Certificate Authority (CA) that issued the certificate is different from the CA currently
configured.
For more information on this feature, see
Administration
Guide.
Details
This directory contains the eDirectory CA certificate in both
DER and PEM formats for use by applications that need them.
The files are named
SSCert.der
respectively.
For example, when PKI Health Check runs, it installs the CA
certificate in the Java Keystore in DER format if the certificate
needs replacing.
"X.509 Certificate
Self-Provisioning" in the
Guide.
"PKI Health
Check" in the
and
,
SSCert.pem
Novell Certificate Server 3.3.4
Novell
Novell Certificate Server 3.3.4
Certificate Management 229

Advertisement

Table of Contents
loading

This manual is also suitable for:

Open enterprise server 2 sp3

Table of Contents