Netscape Signing Tool And Fips-140-1; Using Fips-140 Mode - Netscape MANAGEMENT SYSTEM 6.0 - COMMAND-LINE Manual

Command-line tools guide
Table of Contents

Advertisement

To see fully qualified certificate names when you run Communicator, click the
Security button in Navigator, then click Yours under Certificates in the left frame.
Fully qualified names are of the format smart card:certificate, for example
"
MyCard:My Signing Cert
signtool -k "MyCard:My Signing Cert"
where directory is the directory tree you want to sign.
passwords: the password that protects the Communicator certificate database and
the password that protects your smart card. If the passwords are correct,
signs the files in the directory.

Netscape Signing Tool and FIPS-140-1

This section describes how to use Netscape Signing Tool in FIPS-140-1 validated
mode. FIPS 140-1 is a U.S. government standard for implementations of
cryptographic modules--that is, hardware or software that encrypts and decrypts
data or performs other cryptographic operations (such as creating or verifying
digital signatures). Many products sold to the U.S. government must comply with
one or more of the FIPS standards.

Using FIPS-140 Mode

Verifying FIPS Mode
For general information on FIPS standards and Netscape FIPS-140-1 validation, see
the FIPS 140-1 FAQ.
Using FIPS-140 Mode
Netscape Signing Tool is FIPS-140-1 validated when it uses the FIPS-validated
Netscape cryptographic module. The FIPS module can be activated and
deactivated from within Communicator. Communicator stores the module choice
in the security module database (called
secmodule.db
your certificate database (
the
-d
Before using Netscape Signing Tool in FIPS-validated mode, you must use
Navigator to switch to FIPS mode. For information on how to do this, see
Operating Netscape Navigator in FIPS PUB-140-1 Compliant Mode on Netscape
DevEdge.
on Unix platforms). This database is stored in the same directory as
cert7.db
option of Netscape Signing Tool.
". You use this name with the
directory
secmod.db
) and key database (
Netscape Signing Tool and FIPS-140-1
argument as follows:
-k
asks you for two
signtool
on Windows platforms and
), as indicated by
key3.db
Chapter 13
Netscape Signing Tool
signtool
109

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents