Novell ZENWORKS 10 CONFIGURATION MANAGEMENT SP3 - INSTALLATION 10.3 Installation Manual page 36

Hide thumbs Also See for ZENWORKS 10 CONFIGURATION MANAGEMENT SP3 - INSTALLATION 10.3:
Table of Contents

Advertisement

2 To create a CSR that can be signed by the external CA, enter the following command:
openssl req -new -key zcm.pem -out zcm.csr
When you are asked for "YOUR name," enter the full DNS name assigned to the server where
you are installing ZENworks 10 Configuration Management.
3 To convert the private key from PEM format to DER format, enter the following command:
openssl pkcs8 -topk8 -nocrypt -in zcm.pem -inform PEM -out zcm.der -
outform DER
The private key must be in the PKCS8 DER format, and the signed certificate must be in the
X.509 DER format. You can use the OpenSSL command line tool to convert your keys to the
proper format. This tool can be obtained as part of the Cygwin toolkit, or as part of your Linux
distribution.
4 Use the CSR and generate a certificate by using Novell ConsoleOne, Novell iManager or a true
external CA such as Verisign.
"Generating a Certificate by Using Novell ConsoleOne" on page 36
"Generating a Certificate by Using Novell iManager" on page 37
Generating a Certificate by Using Novell ConsoleOne
1 Ensure that eDirectory is configured as the CA.
2 Issue the certificate for the Primary Server.
2a Launch Novell ConsoleOne.
2b Log in to the eDirectory tree as an administrator with the appropriate rights. For more
information about the appropriate rights, see the
(http://www.novell.com/documentation/crt27/?page=/documentation/crt27/crtadmin/data/
a2zibyo.html#a2zibyo)
2c From the Tools menu, click Issue Certificate.
2d Browse for and select the
2e Click Next.
2f Complete the wizard by accepting the default values.
2g Specify the certificate basic constraints, then click Next.
2h Specify the validity period, the effective and expiration dates then click Next.
2i Click Finish.
2j Choose to save the certificate in the DER-format, and specify a name for the certificate.
3 Export the Organizational CA's self-signed certificate.
3a Log in to eDirectory from ConsoleOne.
3b In the Security container, right-click the CA, then click Properties.
3c In the Certificates tab, select the self-signed certificate.
3d Click Export.
3e When prompted to export the private key, click No.
3f Export the certificate in DER format and choose the location in which you want to save
the certificate.
3g Click Finish.
36
ZENworks 10 Configuration Management Installation Guide
section in the Novell Certificate Server 2.7 documentation.
file.
zcm.csr
Entry Rights Needed to Perform Tasks

Advertisement

Table of Contents
loading

Table of Contents