Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 113

Table of Contents

Advertisement

Log in to the Agent Services interface, check the request for required
f.
extensions. For example, the CRL signing certificate must contain the Key
Usage extension with the
Manager's policy is configured to add the Key Usage extension with
correct bits to the CRL signing certificate; see the policy rule named
CRLSignCertKeyUsageExt
Approve the request.
g.
Once you have the CRL signing certificate ready, restart the wizard and
h.
install the certificate in the Certificate Manager's database.
Stop the Certificate Manager.
2.
Update the Certificate Manager's configuration to recognize the new key pair
3.
and certificate.
In the Certificate Manager host machine, go to this directory:
a.
<server_root>/cert-<instance_id>/config
Open the
b.
CMS.cfg
Add the following lines to the configuration file:
c.
ca.crl_signing.cacertnickname=<nickname> cert-<instance_id>
ca.crl_signing.defaultSigningAlgorithm=<signing_algorithm>
ca.crl_signing.tokenname=<token_name>
Where:
nickname
instance_id
signing_algorithm
token_name
bit set. (By default, the Certificate
crlSigning
, which is an instance of
file in a text editor.
Is the name assigned to the CRL signing
certificate.
Is the name assigned to the Certificate
Manager instance.
Is
MD5withRSA
SHA1withRSA
SHA1withDSA
Is the name of the token used for generating
the key pair and the certificate. If you used
the internal/software token, use
Key Storage Token
Configuring the Certificate Manager
KeyUsageExt
,
, or
MD2withRSA
, if the key type is RSA, or
, if the key type is DSA.
Internal
as the value.
Chapter 3
Certificate Manager
plug-in.)
113

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents