Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 58

Identity server guide
Table of Contents

Advertisement

"c:\Program Files\Java\jdk1.5.0_14\jre\bin\java" -Dprotect=module
-DignorePassphrase=true sun.security.tools.KeyTool -import -alias
od93 –file signcert.der -keystore AMstore.jks -storepass mypwd
-storetype nCipher.sworld -provider
com.ncipher.provider.km.nCipherKM
Enter your values for the following parameters:
Parameter
-Dprotect=module
-DignorePassphrase=true
sun.security.tools.KeyTool
-import
-alias
-file
-keystore
-storepass
-storetype
-provider
10 (Optional) To verify that the certificates have been added to the keystore, enter the following
command:
"c:\Program Files\Java\jdk1.5.0_14\jre\bin\java" -Dprotect=module
-DignorePassphrase=true sun.security.tools.KeyTool -list -v
-keystore AMstore.jks -storetype nCipher.sworld -provider
com.ncipher.provider.km.nCipherKM
The keystore should contain at least two certificates. The certificate that you created should
now be issued by the CA you used, and the public certificate of the CA should be there as the
owner and the issuer.
11 Copy the keystore to the
Linux:
Windows:
The keystore is found on the netHSM client in the directory specified by the -keystore
parameter when you created the keystore. See
58
Novell Access Manager 3.1 SP1 Identity Server Guide
directory on the Identity Server.
idp
/opt/novell/devman/jcc/certs/idp
C:\Program Files\Novell\devman\jcc\certs\idp
Description
Only required if you want the keystore to be
module protected.
Only required if you want the keystore to be
module protected.
The name of the keytool command
The parameter that makes this an import
request.
A name that helps you identify that this is the
signing key pair from the CA. It needs to be the
same alias you specified when you created the
keystore in
Step
4. In this sample configuration,
the name is
.
od93
The name of the signing certificate file from the
CA. In this sample configuration, the name is
.
signcert.der
A name for the keystore. In this sample
configuration, the name is
The password for the keystore. In this sample
configuration, the password is
The type of keystore. For nCipher, this must be
set to
nCipher.sworld
The name of the providerClass and
providerName.
Step
4.
AMstore.jks
.
mypwd
.
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents