Chapter 4. Certificate Manager
CA to issue server certificates and email certificates; cRLSign, which allows a CA to sign CRLS;
and then several options for encrypting data. For the Extended Key Usage extension, there are
several OIDs which can be set for email, server authentication, or client authentication. For more
Section 13.7.8, "Key Usage Extension Default"
information, see
Key Usage Extension
8. Set the constraint values for the CA certificates. There are no constraints to be set for a Key
Usage extension; for an Extended Key Usage extension, set the appropriate OID constraints for
the CA. For more information, see
9. When the changes have been made to the profile, log into the agent services page again, and re-
enable the certificate profile.
For more information on modifying certificate profiles, see
Profiles"
and the Certificate System Agent's Guide.
4.9. Creating Certificate Manager Agents and
Administrators
When the subsystem is configured, there is a default user created with both administrator and agent
privileges. This user can perform both administrator and agent operations and access the Console and
the agent services page.
To create an additional administrator, agent, or auditor, create a user in the Certificate System instance
where the user will have privileges and assign the user to the appropriate group. An agent or auditor
must have a certificate stored in the subsystem's internal database. If the Console is configured for
SSL client authentication, all administrators must also have an SSL client certificate.
To create a new user entry, do the following:
1. Log into the administrative console.
pkiconsole https://server.example.com:9443/ca
2. In the Configuration tab, select Users and Groups. Click Add.
3. Fill in the information in the Edit User Information dialog.
124
Default".
Section 13.7.5, "Extended Key Usage Extension
Section 13.7.5, "Extended
and
Section 13.3, "Setting up Certificate
Default".
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers