Tokens; Installing A Registration Manager - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, check this
document:
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
(Certificate Manager CA signing keys up to 2048 bits in length are not subject to
export restrictions.)
Many people no longer consider an RSA key of length less than 1024 bits to be
cryptographically strong. Export and other regulations permitting, it may be a
good rule of thumb to start with 1024 bits and consider increasing the length to
4096 bits for certificates that provide access to highly sensitive data or services.
However, the question of key length has no simple answers. Every organization
must make its own decision based on its own security requirements. For more
information on key length and encryption strength, see Appendix D of Managing
Servers with Netscape Console.

Tokens

You choose either the
token) or an external token to store the signing certificate and key pair and the SSL
signing certificate and key pair.
If you are using an external token, you will need to install it before you run the
Installation Wizard. In the wizard, you can select from a list of already installed
and available tokens. For example,
"External Token" on page 316.

Installing a Registration Manager

To install a standalone Registration Manager:
Log into Netscape Console as the administrator.
1.
Select the CMS instance and then either click Open, or double click this
2.
instance.
The Installation Wizard launches.
Installation Wizard Introduction. Click Next to continue.
3.
http://www.itl.nist.gov/div897/pubs/fip186.htm
internal
token (if you plan to use the internal/software
. For installation instructions, see
SmartCard
Chapter 4
Installing a Registration Manager
.
Registration Manager
139

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents