Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual page 181

Table of Contents

Advertisement

Token. Enter either
token) or the name of an external token to store the SSL server certificate
and key pair. If you have not previously initialized the token's password,
you must do so in this screen. See "Tokens," on page 173 for more
information.
Key Type. Choose RSA .
Key Length. Available key sizes for RSA are 512, 768, 1024, 2048, 4096, or
Custom. Available key sizes for DSA are 512, 1024, or Custom (which must
be in increments of 64 bits only).
See "Signing Key Type and Length" on page 173 for more information.
Click Next to continue.
Subject Name for SSL Server Certificate. Type the values for the subject DN
18.
components; these values identify the Online Certificate Status Manager's SSL
server certificate. The CN must be the fully-qualified host name of the machine
on which you're installing the Online Certificate Status Manager.
Click Next to continue.
Certificate Extensions for SSL Server Certificate. Select the required
19.
extensions. The default settings should work for most deployments. If
necessary, you can add an additional extension by pasting its base-64 encoding
in the space provided on this screen.
CMS provides command-line tools for generating extensions to include in CA
and other certificate requests. For details about these tools, check this directory:
<server_root>/bin/cert/tools
Note that the certificate extension text field accepts a single extension blob. If
you want to add multiple extensions, you should use the
which is also provided in the
program, see Chapter 5, "Extension Joiner Tool" of CMS
ExtJoiner
Command-Line Tools Guide.
Click Next to continue.
SSL Server Certificate Request Creation. This is an informational screen that
20.
tells you that the wizard has all the information required to generate the key
pair and certificate request. In the previous screen, if you chose to include the
Subject Key Identifier extension in the certificate, you'll be given the choice to
select the format for the certificate request. Otherwise, the request format will
be PKCS #10.
(if you plan to use the internal/software
internal
directory. For details on using the
tools
Installing an Online Certificate Status Manager
ExtJoiner
Chapter 5
OCSP Responder
program,
181

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents