Chapter 13. Basic Subsystem Management
Server
CA
DRM
OCSP
TKS
Apache
RA
TPS
Table 13.1. Certificate System Processes and Their chkconfig Start Priority
13.2. Opening Subsystem Consoles and Services
Each subsystem has different interfaces for different user types to access. All subsystems have some
kind of web services page for agents, administrators, or end users (or all three), with the exception of
the TKS. Additionally, the CA, DRM, TKS, and OCSP all have a Java-based Console, which must be
installed on a server, to perform administrative tasks to manage the subsystem itself.
The appearance and, to a limited extent, functionality of the subsystem's web-based services pages
can be customized to better integrate with an organization's existing websites. See
"Customizing Web Services
13.2.1. Finding the Subsystem Web Services Pages
The CA, RA, DRM, OCSP, TKS, and TPS subsystems have web services pages for agents, regular
users, and administrators. These menu of web services can be accessed by opening the URL to the
subsystem host over the subsystem's secure end user's port. For example, for the CA:
https://server.example.com:9445/ca/services
The main web services page for each subsystem has a list of available services pages; these are
Table 13.2, "Default Web Services
summarized in
the appropriate port and append the appropriate directory to the URL. For example, to access the CA's
end entities (regular users) web services:
https://server.example.com:9444/ca/ee/ca
If DNS is properly configured, then an IPv4 or IPv6 address can be used to connect to the services
pages. For example:
https://1.2.3.4:9445/ca/services
https://[00:00:00:00:123:456:789:00:]:9445/ca/services
Some subsystem interfaces require client authentication to access them, usually interfaces associated
with agent or administrator roles. Other interfaces, even those that run over secure (SSL connections)
do not require client authentication. Some of these interfaces (such as end entities services) can be
configured to require client authentication, but others (such as the configuration wizard) cannot be
configured to support client authentication. These differences are noted in
Services
Pages".
298
Process Name
pki-ca
pki-kra
pki-ocsp
pki-tks
httpd
pki-ra
pki-tps
Pages".
Start Priority
81
82
83
84
85
86
87
Pages". To access any service specifically, access
Shutdown Priority
19
18
17
16
15
14
13
Section 13.3,
Table 13.2, "Default Web
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?