Managing The Certificate Database; Viewing And Deleting Certificate Database Content - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Click Save to save your changes.
6.
You are prompted to restart the server.
Click the Tasks tab and click "Restart the Directory Server."
7.
Close the Directory Server console.
8.
When the server is restarted, from Red Hat Console, open the Directory Server console.
9.
The "Login to Directory" dialog box appears; the Distinguished Name field displays
the Directory Manager DN and you're required to enter the password that corresponds
to this entry.
The Directory Server console (for the internal database) opens only if you enter the
correct password.

Managing the Certificate Database

Each CS instance has a certificate database, which is maintained in its internal token. This
database contains certificates belonging to the subsystem installed in the CS instance and
various CA certificates the subsystems use for validating the certificates they receive.
Whether you use an internal token or an external token for generating and storing key pairs,
CS always maintains its list of trusted and untrusted CA certificates in its internal token.
You may need to add new certificates to the database, remove unwanted certificates from
the database, or change the trust settings of CA certificates in the database. This section
explains how to view the contents of the certificate database, delete unwanted certificates,
and change the trust settings of CA certificates installed in the database using the CS
window. For information on adding certificates to the database, see "Certificate Setup
Wizard" on page 289.
NOTE

Viewing and Deleting Certificate Database Content

As an administrator, you should periodically check the contents of the certificate database
and make sure that it doesn't include any unwanted CA certificates. For example, if the
database includes CA certificates that you don't ever want to trust in your PKI setup, you
should delete them.
CS also provides a command-line utility called
its certificate database. For details about this tool, check this site:
http://www.mozilla.org/projects/security/pki/nss/tools/
Managing the Certificate Database
for managing
certutil
Chapter 8
Administrative Basics
285

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents