7. Click OK.
The new certificate is listed in the Your certificates tab.
NOTE
If there are multiple client certificates installed, the Certificate System subsystem may not
automatically find the appropriate client certificate. Set the Ask every time in the Client
certificate selection section of the Firefox Advanced tab, which will prompt for the user
to select the client certificate every time a website requests one.
10.4. Managing the Certificate Database
Each Certificate System instance has a certificate database, which is maintained in its internal token.
This database contains certificates belonging to the subsystem installed in the Certificate System
instance and various CA certificates the subsystems use for validating the certificates they receive.
Even if an external token is used to generate and store key pairs, Certificate System always maintains
its list of trusted and untrusted CA certificates in its internal token.
This section explains how to view the contents of the certificate database, delete unwanted
certificates, and change the trust settings of CA certificates installed in the database using the
Certificate System window. For information on adding certificates to the database, see
"Installing Certificates in the Certificate System
NOTE
The Certificate System command-line utility certutil can be used to manage the
certificate database by editing trust settings and adding and deleting certificates. For
details about this tool, see http://www.mozilla.org/projects/security/pki/nss/tools/.
Administrators should periodically check the contents of the certificate database to make sure that it
does not include any unwanted CA certificates. For example, if the database includes CA certificates
that should not ever be trusted within the PKI setup, delete them.
10.4.1. Installing Certificates in the Certificate System Database
If new server certificates are issued for a subsystem, they must be installed in that subsystem
database. Additionally, user and agent certificates must be installed in the subsystem databases. If the
certificates are issued by an external CA, then usually the corresponding CA certificate or certificate
chain needs installed.
Certificates can be installed in the subsystem certificate database through the Console's Certificate
Setup Wizard or using the certutil utility.
Section 10.4.1.1, "Installing Certificates through the Console"
•
Section 10.4.1.2, "Installing Certificates Using certutil"
•
Section 10.4.1.3, "About CA Certificate Chains"
•
Section 10.4.1.4, "Importing Cross-Pair Certificates"
•
Managing the Certificate Database
Database".
Section 10.4.1,
221
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers