Generating The Certificate Authority Ssl Key Pair - Red Hat NETWORK SATELLITE 5.2 - CLIENT Configuration Manual

Client configuration
Hide thumbs Also See for NETWORK SATELLITE 5.2 - CLIENT:
Table of Contents

Advertisement

Option
--rpm-only
--no-rpm
--server-rpm=SERVER_RPM
--server-tar=SERVER_TAR
Table 3.2. SSL Web Server Options (rhn-ssl-tool --gen-server --help)

3.2.3. Generating the Certificate Authority SSL Key Pair

Before creating the SSL key set required by the Web server, you must generate a Certificate Authority
(CA) SSL key pair. A CA SSL public certificate is distributed to client systems of the Satellite or Proxy.
The RHN SSL Maintenance Tool allows you to generate a CA SSL key pair if needed and re-use it
for all subsequent RHN server deployments.
The build process automatically creates the key pair and public RPM for distribution to clients. All CA
components end up in the build directory specified at the command line, typically /root/ssl-build
(or /etc/sysconfig/rhn/ssl for older Satellites and Proxies). To generate a CA SSL key pair,
issue a command like this:
rhn-ssl-tool --gen-ca --password=MY_CA_PASSWORD --dir="/root/ssl-build"
\ --set-state="North Carolina" --set-city="Raleigh" --set-org="Example
Inc." \ --set-org-unit="SSL CA Unit"
Replace the example values with those appropriate for your organization. This will result in the
following relevant files in the specified build directory:
• RHN-ORG-PRIVATE-SSL-KEY — the CA SSL private key
• RHN-ORG-TRUSTED-SSL-CERT — the CA SSL public certificate
• rhn-org-trusted-ssl-cert-VER-REL.noarch.rpm — the RPM prepared for distribution to
client systems. It contains the CA SSL public certificate (above) and installs it in this location: /usr/
share/rhn/RHN-ORG-TRUSTED-SSL-CERT
• rhn-ca-openssl.cnf — the SSL CA configuration file
• latest.txt — always lists the latest versions of the relevant files.
Once finished, you're ready to distribute the RPM to client systems. Refer to
the CA SSL Public Certificate to
Generating the Certificate Authority SSL Key Pair
Clients".
Description
Rarely used - Generate only an RPM for
deployment. Review --gen-server --
rpm-only --help for more information.
Rarely used - Conduct all server-related
steps except RPM generation.
Rarely changed - RPM name that houses
the Web server's SSL key set (the
base filename, not filename-version-
release.noarch.rpm).
Rarely changed - Name of .tar archive of
the Web server's SSL key set and CA public
certificate that is used solely by the hosted
RHN Proxy Server installation routines
(the base filename, not filename-version-
release.tar).
Section 3.3, "Deploying
17

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETWORK SATELLITE 5.2 - CLIENT and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents