Diagnostics; Testing The Cloned Configuration - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

its operations. Before installing and configuring the clone, the master subsystem must be installed,
fully configured, and running.
A cloned subsystem is configured through standard configuration wizard. Before going through the
setup process, some manual preparation is required. To prepare for cloning, do the following:
• If the keys and certificates are stored in the Internal Key Storage Token (software token).
When configuring the master instance, select yes in the Export Keys and Certificates panel to
back up the keys and certificates, and enter the password to protect the PKCS #12 file. Then restart
the master instance when configuration is complete.
If the keys and certificates were not backed up when the master instance was configured, they can
be backed up using the pk12util tool.
When configuring the clone instance, enter the location and the password for the PKCS #12 file in
the Restore Keys and Certificates screen. Then restart the clone instance when configuration is
complete.
• If the keys and certificates are stored on a hardware token.
• Duplicate all the required keys and certificates, except the SSL server key and certificate to the
clone instance. Keep the nicknames for those certificates the same. Additionally, copy all the
necessary trusted root from the master instance to the clone instance.
• If the token is network-based, then the keys and certificates simply need to be available to the
token; the keys and certificates do not need to be copied.
• When using a network-based hardware token, make sure the high-availability feature is enabled
on the hardware token to avoid single point of failure.

20.2.1. Diagnostics

Use the certutil tool to list all the certificates in the clone instance to make sure that all the required
certificates are in place.

20.3. Testing the Cloned Configuration

To test the CA clone, do the following:
1. Request a certificate from the cloned CA.
2. Approve the request.
3. Download the certificate to the browser.
4. Revoke the certificate.
5. Check master CA's CRL for the revoked certificate. In the master Certificate Manager's agent
services page, click Update Certificate Revocation List. Find the CRL in the list.
The CRL should show the certificate revoked by the cloned Certificate Manager. If that certificate
is not listed, check logs to resolve the problem.
To test the OCSP clone, do the following:
Diagnostics
453

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents