Deploying Client Ssl Certificates; Configuring The Clients - Red Hat NETWORK SATELLITE 5.1.1 Reference Manual

Hide thumbs Also See for NETWORK SATELLITE 5.1.1:
Table of Contents

Advertisement

Chapter 9. UNIX Support Guide
# export MANPATH
Alternatively, you can also access the man pages from the command line, with the following
command:
# man -M /opt/redhat/rhn/solaris/man <man page>
Finally, add the Red Hat Libraries to your PATH as you did with libgcc, openssl and zlib.
crle -c /var/ld/ld.config -l <current library paths>:/opt/redhat/rhn/
solaris/lib

9.3.2. Deploying Client SSL Certificates

To ensure secure data transfer, Red Hat strongly recommends the use of SSL. The RHN Satellite
Server eases implementation of SSL by generating the necessary certificates during its installation.
The server-side certificate is automatically installed on the Satellite itself, while the client certificate is
placed in the /pub/ directory of the Satellite's Web server.
To install the certificate, follow these steps for each client:
1. Download the SSL certificate from the /var/www/html/pub/ directory of the RHN Satellite
Server onto the client system. The certificate will be named something similar to RHN-ORG-
TRUSTED-SSL-CERT. It is accessible via the web at the following URL: https://your-
satellite.example.com/pub/RHN-ORG-TRUSTED-SSL-CERT.
2. Move the client SSL certificate to the RHN-specific directory for your UNIX variant. For Solaris, this
can be accomplished with a command similar to:
mv /path/to/RHN-ORG-TRUSTED-SSL-CERT /opt/redhat/rhn/solaris/usr/
share/rhn/
When finished, the new client certificate will be installed in the appropriate directory for your UNIX
system. If you have a large number of systems to prepare for RHN management, you may script this
entire process.
Now you must reconfigure the RHN client applications to refer to the newly installed SSL certificate.
Section 9.3.3, "Configuring the clients"
Refer to

9.3.3. Configuring the clients

The final step before registering your client systems with Red Hat Network is to reconfigure their RHN
applications to use the new SSL certificate and obtain updates from the RHN Satellite Server. Both
of these changes can be made by editing the configuration file of the Red Hat Update Agent, which
provides registration and update functionality.
Follow these steps on each client system:
1. As root, change to the RHN configuration directory for the system. For Solaris, the full path is /
opt/redhat/rhn/solaris/etc/sysconfig/rhn/.
182
for instructions.

Advertisement

Table of Contents
loading

Table of Contents