Managing Certificates And The Certificate Database - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Configuring a Registration Manager
Managing Certificates and the Certificate
Database
The signing certificate and SSL encryption certificate are created and installed
during the installation of the Registration Manager. See "Registration Managers
Certificates," on page 135 for more information about these certificates and the
things you should consider before getting these certificates.
CMS contains a Certificate Wizard that allows you to create additional certificates,
or to renew or replace a certificate for the Registration Manager. See "Certificate
Setup Wizard," on page 298 for details of using the wizard and about renewing or
replacing a subsystem certificate.
Trust Settings and CA Certificates
The trusted database also contains the CA certificates for those CAs that the
subsystem trusts. If your subsystem has certificates from a CA or accepts
certificates that are issued by a CA, it must have a copy of those CA certificates in
the trusted database, and they must be configured as trusted, see "Changing the
Trust Settings of a CA Certificate," on page 296 and "Installing a New CA
Certificate in the Certificate Database," on page 297.
Certificate Chain
You also may need to install a certificate chain in the database to provide the chain
of CAs to a trusted CA. You can install a certificate chain in the certificate database,
see "Installing a CA Certificate Chain in the Certificate Database," on page 298.
Getting Additional SSL Server Certificates
The Registration Manager uses its SSL server certificate to do SSL server-side
authentication to the following:
The End-Entity Services interface (the HTTPS port)
The Registration Manager Agent Services interface
By default, the Registration Manager uses a single SSL server certificate for
authentication purposes. However, you can request and install additional SSL
server certificates for the Registration Manager. For example, you can configure the
Registration Manager to use separate server certificates for authenticating to
Netscape Console, the end entity services interface, and the Registration Manager
Agent Services interface. For instructions, see "Configuring the Server to Use
Separate SSL Server Certificates" on page 321.
154
Netscape Certificate Management System Administrator's Guide • February 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents