Installing A Ca Certificate Chain In The Certificate Database; Certificate Setup Wizard - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Managing the Certificate Database
When the Registration Manager attempts to request a service from the Certificate
Manager (using the renewed certificate for SSL client authentication), the
Certificate Manager fails to authenticate the Registration Manager. This happens
because, as a part of validating the certificate presented by the Registration
Manager, the Certificate Manager checks its certificate database for the CA that
signed the Registration Manager's certificate. The Certificate Manager does not
find the CA listed in its trust database as a trusted CA, so it rejects the Registration
Manager's service request.
The Certificate Setup Wizard built into the CMS window automates the process of
installing trusted CA certificates in the certificate database. For instructions on
using the wizard, see "Using the Wizard to Install a Certificate or Certificate
Chain" on page 307.
NOTE
Installing a CA Certificate Chain in the Certificate
Database
Any client or server software that supports certificates maintains a collection of
trusted CA certificates in its certificate database. These CA certificates determine
which other certificates the software can validate—in other words, which issuers of
certificates the software can trust. In the simplest case, the software can validate
only certificates issued by one of the CAs for which it has a certificate. It's also
possible for a trusted CA certificate to be part of a chain of CA certificates, each
issued by the CA above it in a certificate hierarchy; for details on certificate
hierarchies and certificate chains, see "How CA Certificates Are Used to Establish
Trust" in Appendix D of Managing Servers with Netscape Console.

Certificate Setup Wizard

CMS provides a wizard, called the Certificate Setup Wizard, which automates the
process of requesting and installing the certificates required by the CMS
manager—Certificate Manager, Registration Manager, Data Recovery Manager, or
Online Certificate Status Manager—installed in a CMS instance.
296
Netscape Certificate Management System Administrator's Guide • June 2003
Be sure to choose the "Other Trusted CAs" option in Step 2 of the
wizard process.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents