16.1.1.4. SSL Server Key Pair and Certificate
Every Certificate Manager has at least one SSL server certificate that was first generated when
the Certificate Manager was installed. The default nickname for the certificate is Server-Cert
cert-instance_ID, where instance_ID identifies the Certificate Manager instance.
The Certificate Manager SSL server certificate was issued by the CA to which the certificate signing
request was submitted, which is the Certificate Manager itself, another Certificate System CA, or a
public CA.
By default, the Certificate Manager uses a single SSL server certificate for authentication. However,
additional server certificates can be requested to use for different operations, such as configuring the
Certificate Manager to use separate server certificates for authenticating to the end-entity services
interface and agent services interface.
If the Certificate Manager is configured for SSL-enabled communication with a publishing directory,
it uses its SSL server certificate for client authentication to the publishing directory by default. The
Certificate Manager can also be configured to use a different certificate for SSL client authentication.
16.1.1.5. Audit Log Signing Key Pair and Certificate
The CA keeps a secure audit log of all events which occurred on the server. To guarantee that the
audit log has not been tampered with, the log file is signed by a special log signing certificate.
The audit log signing certificate is issued when the server is first configured.
16.1.2. RA Certificates
An RA only uses two certificates: an SSL server certificate and a subsystem certificate.
Section 16.1.2.1, "SSL Server Certificate"
•
Section 16.1.2.2, "Subsystem Certificate"
•
16.1.2.1. SSL Server Certificate
Every Certificate System RA has at least one SSL server certificate. The first SSL server certificate
is generated when the RA is configured. The default nickname for the certificate is Server-Cert
cert-instance_id.
The RA uses its SSL server certificate for server-side authentication to the RA admin and agent
services web pages.
16.1.2.2. Subsystem Certificate
Every member of the security domain is issued a server certificate to use for communications
among other domain members. The RA is issued the subsystem certificate when the instance is first
configured, as with its SSL certificate.
The default nickname for the certificate is subsystemCert cert-instance_id.
16.1.3. Online Certificate Status Manager Certificates
When the Online Certificate Status Manager is first configured, the keys for all required certificates
are created, and the certificate requests for the OCSP signing, SSL server, audit log signing, and
RA Certificates
389
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?