For more information on the pkicreate tool options, see the Certificate System Command-Line
Tools Guide.
2. When the instance is successfully created, the process returns a URL for the HTML configuration
page. For example:
http://server.example.com:10180/kra/admin/console/config/login?pin=nt2z2keqcqAZiBRBGLDf
3. Open the new instance URL, and go through the configuration wizard as described in
"Configuring the Default Subsystem
internal LDAP database, and agent information.
4. When the configuration is complete, restart the subsystem.
/etc/init.d/instance_ID restart
2.7.2. Running pkicreate with Port Separation
To create an instance with three separate ports for the different subsystem services, run pkicreate
with three options which specify the services ports: -admin_secure_port, -agent_secure_port,
and -ee_secure_port. For CAs only, there is an additional port for end-entity client authentication, -
ee_secure_client_auth_port.
1. Run the pkicreate command. For example:
pkicreate -pki_instance_root=/var/lib/pki-ca2 -subsystem_type=ca -pki_instance_name=pki-
ca2 -admin_secure_port=9545 -agent_secure_port-9544 -ee_secure_port=9543 -
ee_secure_client_auth_port=9546 -unsecure_port=9180 -tomcat_server_port=1802 -verbose
2. When the instance is successfully created, the process returns a URL for the HTML configuration
page. For example:
http://server.example.com:10180/kra/admin/console/config/login?pin=nt2z2keqcqAZiBRBGLDf
3. Open the new instance URL, and go through the configuration wizard as described in
"Configuring the Default Subsystem
internal LDAP database, and agent information.
4. When the configuration is complete, restart the subsystem.
/etc/init.d/instance_ID restart
For more information on the pkicreate tool options, see the Certificate System Command-Line Tools
Guide.
2.8. Cloning a Subsystem
For failover protection and for availability for high-traffic subsystems, it is possible to clone an existing
CA, RA, DRM, TKS, or OCSP subsystem. To clone a subsystem:
1. Create a new instance using pkicreate.
Instances". Supply the security domain, CA, instance ID,
Instances". Supply the security domain, CA, instance ID,
Running pkicreate with Port Separation
Section 2.6,
Section 2.6,
53
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers