Cloning the Online Certificate Status Manager
Cloning the OCSP Responder
The following are the steps to setup cloning for an Online Certificate Status Manager:
From the Object menu in the Red Hat Console, choose Create Instance Of, then choose
1.
Red Hat Certificate System. Alternatively, you can right-click the Server Group node
and choose Create Instance Of > Red Hat Certificate System. The admin console asks
you to provide a name for the new instance; enter the name of the new Online
Certificate Status Manager instance in the dialog provided.
The Installation Wizard displays a dialog asking you to specify whether this new
2.
instance is a clone. Answer Yes and click Next.
The Installation Wizard asks you to copy the key and certificates from the master
3.
OCSP Responder to the clone if you have not already done so.
Copy the master OCSP Responder's Certificate and Key Database.
4.
Because you want the cloned Online Certificate Status Manager to own the same keys
and certificates as that of the master Online Certificate Status Manager, you need to
make the keys and certificates used by the master available to the Online Certificate
Status Manager clone.
❍
❍
Open the Server Group item, select the cloned OCSP Responder, and click Open again
5.
to resume configuration where you left off in the installation wizard.
664
Red Hat Certificate System Administrator's Guide • September 2005
If the master Online Certificate Status Manager's keys and certificates are stored
in the internal/software token, you need to copy the certificate and key database
files from the master to the Online Certificate Status Manager clone. Here's how
you do this:
In the master Online Certificate Status Manager's host machine, go to this
I.
directory:
<server_root>/alias
Locate the certificate and key database files for the Online Certificate Status
II.
Manager; the file names are as follows:
cert-<ocsp_instance_id>-<machine_name>-cert8.db
cert-<ocsp_instance_id>-<machine_name>-key3.db
On the host machine of the clone, go to this directory:
III.
<server_root>/alias
Copy the certificate and key database files from the master Online Certificate
IV.
Status Manager to the clone.
If the master Online Certificate Status Manager's keys and certificates are stored
in the hardware token, you need to copy the keys and certificates following the
instructions provided by the hardware-token vendor.
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?