its operations. Before installing and configuring the clone, the master subsystem must be installed,
fully configured, and running.
A cloned subsystem is configured through standard configuration wizard. Before going through the
setup process, some manual preparation is required. To prepare for cloning, do the following:
• If the keys and certificates are stored in the Internal Key Storage Token (software token).
When configuring the master instance, select yes in the Export Keys and Certificates panel to
back up the keys and certificates, and enter the password to protect the PKCS #12 file. Then restart
the master instance when configuration is complete.
If the keys and certificates were not backed up when the master instance was configured, they can
be backed up using the pk12util tool.
When configuring the clone instance, enter the location and the password for the PKCS #12 file in
the Restore Keys and Certificates screen. Then restart the clone instance when configuration is
complete.
• If the keys and certificates are stored on a hardware token.
• Duplicate all the required keys and certificates, except the SSL server key and certificate to the
clone instance. Keep the nicknames for those certificates the same. Additionally, copy all the
necessary trusted root from the master instance to the clone instance.
• If the token is network-based, then the keys and certificates simply need to be available to the
token; the keys and certificates do not need to be copied.
• When using a network-based hardware token, make sure the high-availability feature is enabled
on the hardware token to avoid single point of failure.
20.2.1. Diagnostics
Use the certutil tool to list all the certificates in the clone instance to make sure that all the required
certificates are in place.
20.3. Testing the Cloned Configuration
To test the CA clone, do the following:
1. Request a certificate from the cloned CA.
2. Approve the request.
3. Download the certificate to the browser.
4. Revoke the certificate.
5. Check master CA's CRL for the revoked certificate. In the master Certificate Manager's agent
services page, click Update Certificate Revocation List. Find the CRL in the list.
The CRL should show the certificate revoked by the cloned Certificate Manager. If that certificate
is not listed, check logs to resolve the problem.
To test the OCSP clone, do the following:
Diagnostics
453
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers