Chapter 2. Installation and Configuration
Figure 2.9. Configuring the Internal LDAP Database Information
NOTE
Do not share the same suffix and database name for more than one Certificate System
subsystem. The same instance can be used for more than one subsystem, but different
suffix and database names must be specified. Additionally, if a subsystem is being cloned,
the same directory instance cannot be used for both the master and clone.
If a subsystem is cloned, the configuration wizard attempts to configure multi-master replication
agreements between the master subsystem's internal database and the new clone's internal database.
2.4.9. Key Store Panel
This panel displays a list of automatically-discovered tokens that can be used to store certificates
and keys. The Certificate System automatically discovers Safenet's LunaSA and nCipher's netHSM
hardware security modules (HSM) and returns them on this screen. The discovery process assumes
that the client software installations for these modules are local on the same system as the Certificate
System subsystem and are in the following locations:
• LunaSA: /usr/lunasa/lib/libCryptoki2.so
• nCipher: /opt/nfast/toolkits/pkcs11/libcknfast.so
NOTE
Previously, all possible slots had to be logged into before configuration could proceed; in
Certificate System 7.3 it is possible to configure the instance while being logged into only
one slot.
40
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers