new_HSM_slot_name:Server-Cert cert-old_DRM_instance
3. Netscape Certificate Management System 4.2
(SP 2) and 4.5 and iPlanet Certificate Management
System 4.7
There are three subsystems that can be migrated from Netscape Certificate Management System 4.2 (SP2) and 4.5 and
iPlanet Certificate Management System 4.7 to a later version of the Certificate System: the Certificate Authority (CA),
Data Recovery Manager (DRM), and Online Certificate Status Protocol (OCSP). Each subsystem has different migration
procedures.
•
Section 3.1, "4.2SP2, 4.5, and 4.7 Certificate Authority (CA) Migration"
•
Section 3.2, "4.2SP2, 4.5, and 4.7 Data Recovery Manager (DRM) Migration"
•
Section 3.3, "4.2SP2, 4.5, and 4.7 Online Certificate Status Protocol (OCSP) Migration"
3.1. 4.2SP2, 4.5, and 4.7 Certificate Authority (CA) Migration
Determine if the Certificate Management System Certificate Authority (CA) being migrated uses security databases, HSM,
or both. There are four possible migration scenarios; follow the appropriate process for the deployment scenario being mi-
grated.
•
Section 3.1.1, "Case I: Security Databases to Security Databases Migration"
•
Section 3.1.2, "Case II: Security Databases to HSM Migration"
•
Section 3.1.3, "Case III: HSM to Security Databases Migration"
•
Section 3.1.4, "Case IV: HSM to HSM Migration"
3.1.1. Case I: Security Databases to Security Databases Migration
1.
Remove all the security databases in the new Certificate System which will receive migrated data.
rm /var/lib/instance_ID/alias/cert8.db
rm /var/lib/instance_ID/alias/key3.db
2.
Copy the certificate and key security databases from the old server to the new server.
cp old_server_root/cert-old_CA_instance/config/cert-old_CA_instance-cert7.db
/var/lib/instance_ID/alias/cert7.db
cp old_server_root/cert-old_CA_instance/config/cert-old_CA_instance-key3.db
/var/lib/instance_ID/alias/key3.db
3.
Log into the new Certificate System server as the Certificate System user, and open the alias/ directory.
cd /var/lib/instance_ID/alias/
4.
Log in as root, and set the file user and group to the Certificate System user and group.
su
chown user:group cert7.db
3. Netscape Certificate Manage-
ment System 4.2 (SP 2) and 4.5
Databases
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE and is the answer not in the manual?
Questions and answers