Internal Token; External Token; Installing External Tokens - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Internal Token

An internal (software) token refers to a pair of software files, usually called
certificate database and key database, that Certificate Management System uses to
generate and store its key pairs and certificates. Certificate Management System
automatically generates these files in the file system of its host machine when you
choose to use the internal token for the first time. These files were created for you
during CMS installation if you chose to use the internal token for key-pair
generation.
In the CMS host system, the certificate database is identified by the name
; the key database is identified by the name
cert7.db
these files at this location:

External Token

An external (hardware) token refers to an external hardware device, such as a
smart card, FORTEZZA card, or other crypto card, that Certificate Management
System uses to generate and store its key pairs and certificates. Certificate
Management System supports any hardware tokens that are compliant with
PKCS#11 version 2.01. For details, see the information provided at this URL:
http://developer.netscape.com/support/faqs/pkcs_11.html
If you haven't already done so, consider using external tokens for generating and
storing the key pairs and certificates used by Certificate Management System.
These devices represent another security measure you can take to safeguard
private keys because hardware tokens are sometimes considered more secure than
software tokens. For additional details, check the literature provided by
hardware-token vendors.

Installing External Tokens

To use external encryption devices or tokens, you need to take the following steps:
Step 1. Install the Cryptographic Device
Step 2. Install the PKCS #11 Module
Step 1. Install the Cryptographic Device
To install the drivers provided by the device manufacturer, follow the instructions
that came with the device. When you install a hardware token, you are given an
opportunity to name it; be sure to use a name that will help you identify the token
later.
<server_root>/cert-<instance_id>/config
Chapter 14
Tokens for Storing CMS Keys and Certificates
. You can find both
key3.db
Managing CMS Keys and Certificates
451

Advertisement

Table of Contents
loading

Table of Contents