Keys and Certificates for the Main Subsystems
To request and install a CRL signing certificate for a Certificate Manager using
its Certificate Setup Wizard, follow these instructions:
a.
b.
c.
d.
e.
f.
g.
h.
i.
440
Netscape Certificate Management System Installation and Setup Guide • October 2001
Use the Key Database (
Database (
) tool to request a certificate for the key pair and install
certutil
the certificate in the Certificate Manager's certificate database. For more
information about the Key Database and Certificate Database tools, see
CMS Command-Line Tools Guide.
Log in to Netscape Console; see "Logging In to Netscape Console" on
page 336.
Locate the CMS instance for the Certificate Manager, make sure it's started,
and then log in to the CMS window of the Certificate Manager.
Select the Configuration tab, and then select the Encryption tab.
Click the Certificate Setup Wizard button to launch the wizard, which is
explained in "Certificate Setup Wizard" on page 456.
Select the option to request a certificate and then follow the on-screen
prompts to generate a certificate request for the CRL signing certificate—in
the Certificate Selection window, select
as the certificate type in the associated text field.
Once you have the certificate request ready, submit it to the Certificate
Manager so that it can issue a certificate—in the request submission screen
of the wizard, use the auto-submission feature by entering the Certificate
Manager's hostname and port number so that the request gets added to the
Certificate Manager's agent queue. For general instructions to use the
wizard to request a certificate, see section "Using the Wizard to Request a
Certificate" on page 457.
Log in to the Agent Services interface, check the request for required
extensions. For example, the CRL signing certificate must contain the Key
Usage extension with the
Manager's policy is configured to add the Key Usage extension with
correct bits to the CRL signing certificate; see the policy rule named
CRLSignCertKeyUsageExt
Approve the request.
Once you have the CRL signing certificate ready, restart the wizard and
install the certificate in the Certificate Manager's database. For general
instructions to use the wizard to add a certificate, see "Using the Wizard to
Install a Certificate or Certificate Chain" on page 471.
) tool to generate a key pair, the Certificate
keyutil
Other
bit set. (By default, the Certificate
crlSigning
, which is an instance of
and specify
caCrlSigning
plug-in.)
KeyUsageExt
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 and is the answer not in the manual?