Crl Signing Key Pair And Certificate - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

CRL Signing Key Pair and Certificate

By default, a Certificate Manager you have installed uses the same key pair, the one
that corresponds to the CA signing certificate explained in "CA Signing Key Pair and
Certificate" on page 421, for signing certificates and certificate revocation lists
(CRLs). For details about CRLs, see "What's a CRL?" on page 591.
If you want a Certificate Manager to use a separate key pair for signing the CRL it
generates, you can do so after installation. The instructions are provided below.
Note that a Certificate Manager's CRL signing certificate must be signed or issued
by itself; make sure you submit the request to the Certificate Manager itself.
Request and install a CRL signing certificate for the Certificate Manager. To do
1.
this, you may use either of these options:
Use the Certificate Setup Wizard available within the CMS window.
Use the Key Database (
Database (
certutil
the certificate in the Certificate Manager's certificate database. For more
information about the Key Database and Certificate Database tools, see
CMS Command-Line Tools Guide.
To request and install a CRL signing certificate for a Certificate Manager using
its Certificate Setup Wizard, follow these instructions:
Log in to Netscape Console; see "Logging In to Netscape Console" on
a.
page 326.
Locate the CMS instance for the Certificate Manager, make sure it's started,
b.
and then log in to the CMS window of the Certificate Manager.
Select the Configuration tab, and then select the Encryption tab.
c.
Click the Certificate Setup Wizard button to launch the wizard, which is
d.
explained in "Certificate Setup Wizard" on page 436.
Select the option to request a certificate and then follow the on-screen
e.
prompts to generate a certificate request for the CRL signing certificate—in
the Certificate Selection window, select
as the certificate type in the associated text field.
) tool to generate a key pair, the Certificate
keyutil
) tool to request a certificate for the key pair and install
Other
Chapter 14
Keys and Certificates for the Main Subsystems
and specify
caCrlSigning
Managing CMS Keys and Certificates
423

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents