Sign In
Upload
Manuals
Brands
Netscape Manuals
Software
Certificate Management System 6.1
Netscape Certificate Management System 6.1 Manuals
Manuals and User Guides for Netscape Certificate Management System 6.1. We have
3
Netscape Certificate Management System 6.1 manuals available for free PDF download: Administrator's Manual, Manual
Netscape Certificate Management System 6.1 Administrator's Manual (840 pages)
Brand:
Netscape
| Category:
Software
| Size: 6 MB
Table of Contents
Table of Contents
3
About this Guide
21
What You Should Know
21
Who Should Read this Guide
21
What's in this Guide
22
Conventions Used in this Guide
25
Documentation
26
Chapter 1 Overview
29
Features
29
Subsystems
29
Certificate Manager Flexibility and Scalability
30
Interfaces
31
Logging
31
Auditing
32
Self Tests
32
Authorization
32
Authentication
32
Certificate Issuance
33
Certificate Profiles
33
Policy
34
Crls
34
Publishing
34
Notifications
35
Jobs
35
Dual Key Pairs
35
Hsms and Crypto Accelerators
35
Support for Open Standards
36
Java SDK Extension Mechanism for Customization
37
How Certificate Management System Works
37
CMS Basics
37
About the Certificate Manager
40
How the Certificate Manager Works
42
About the Registration Manager
45
How the Registration Manger Works
46
Data Recovery Manager
49
Online Certificate Status Manager
50
Deployment Scenarios
50
Single Certificate Manager
50
Certificate Manager and Registration Manager
51
Certificate Manager and Data Recovery Manager
53
Certificate Manager, Data Recovery Manager, and Registration Manager
55
Cloned Certificate Manager
56
System Architecture
57
CMS Component
58
HTTP Engine
59
Service Interfaces
60
JSS and the Java/Jni Layer
61
Nss
62
Pkcs #11
62
Management Tools
63
Jre
63
Internal LDAP Database
64
Administration Server
64
Cms Sdk
64
Support for Open Standards
65
Certificate Management Formats and Protocols
65
Security and Directory Protocols
66
Chapter 2 Installation
69
Installation and Configuration Overview
69
Installation and Configuration Process
70
Installation Overview
71
About the Installation Program
71
Installation Considerations
71
Installation Worksheet
76
Installing CMS
77
Uninstalling CMS
81
Chapter 3 Certificate Manager
83
Certificate Manager Deployment Considerations
83
Self-Signed Root Vs. Subordinate CA
84
Cloned CA
85
Certificate Manager Certificates
85
Certificate Manager Interfaces
89
Password Storage
90
Internal Database
90
Tokens
91
Installing a Certificate Manager
91
Installing a Certificate Manager as a Root CA
91
Installing a Certificate Manager as a Subordinate CA
96
Configuring the Certificate Manager
110
Adding Users
110
Configuring Authorization
110
Managing Certificates and the Certificate Database
111
Changing Ports and IP Addresses
115
Changing Subsystem Security Setting
116
Changing Passwords or Storage Settings
116
Configuring Logs
116
Changing Internal Database Settings
116
Configuring Self Test
116
Setting up a Mail Server
117
Changing the Certificate Issuance Rules
117
Setting up Authentication
118
Configuring Policies
120
Configuring Certificate Profiles
121
Configuring Publishing
121
Configuring OCSP Services
122
Setting up Crls
122
Setting up Notifications
122
Setting up Jobs
123
Customizing the End Entity Interface
123
Adding Data Recovery Services
123
How the Certificate Manager Works
123
Enrollment
124
Renewal
126
Revocation
126
Federal Bridge CA
127
Issuing Cross-Pair Certificates
128
Importing Cross-Pair Certificates
128
Publishing Cross-Pair Certificates
128
Cloning a CA
129
Cloning Considerations
130
Setting up a Clone CA
131
Testing the Clone-Master Connection
134
Chapter 4 Registration Manager
135
Registration Manager Deployment Considerations
135
Registration Managers Certificates
135
Registration Manager Interfaces
137
Password Storage
138
Internal Database
138
Signing Key Type and Length
138
Tokens
139
Installing a Registration Manager
139
Configuring a Registration Manager
152
Setting up Trust with a CA
152
Adding Users
152
Configuring Authorization
153
Managing Certificates and the Certificate Database
154
Changing Ports and IP Addresses
155
Changing Subsystem Security Setting
155
Changing Passwords or Storage Settings
155
Configuring Logs
156
Changing Internal Database Settings
156
Configuring Self Test
156
Setting up a Mail Server
156
Setting up Authentication
157
Configuring Policies
158
Configuring Certificate Profiles
159
Crls
160
Setting up Notifications
160
Setting up Jobs
161
Customizing the End Entity Interface
161
Adding Data Recovery Services
161
How a Registration Manager Works
161
Enrollment
161
Renewal
164
Revocation
164
Chapter 5 OCSP Responder
167
About OCSP Services
167
How OCSP Services Work
168
OCSP Response Signing
168
OCSP Responses
169
CMS OCSP Services
170
Setting up a Certificate Manager with OCSP Service
171
Online Certificate Status Manager Deployment Considerations
172
Online Certificate Status Manager Certificates
172
Interfaces
174
Password Storage
175
Tokens
175
Internal Database
175
Signing Key Type and Length
175
Installing an Online Certificate Status Manager
176
Setting up the OCSP Responder
188
Configuring the Online Certificate Status Manager
189
Adding Users
189
Configuring Authorization
189
Managing Certificates and the Certificate Database
190
OCSP Certificates
191
Changing Ports and IP Addresses
192
Changing Subsystem Security Setting
192
Changing Passwords or Storage Settings
192
Configuring Logs
192
Changing Internal Database Settings
193
Configuring Self Test
193
Setting up Jobs
193
Identifying the CA to the OCSP Responder
193
Configure the Revocation Info Stores
195
Testing Your OCSP Setup
197
Chapter 6 Data Recovery Manager
199
PKI Setup for Key Archival and Recovery
199
Clients that Can Generate Dual Key Pairs
200
Data Recovery Manager
200
Forms for Users and Key Recovery Agents
201
Key Archival Process
201
Why You Should Archive Keys
201
Where the Keys Are Stored
202
How Key Archival Works
203
Key Recovery Process
205
Key Recovery Agents and Their Passwords
205
How Agent-Initiated Key Recovery Works
208
Key Recovery Agent Scheme
211
Installing a Standalone Data Recovery Manager
215
Data Recovery Manager's Key Pairs and Certificates
215
Tokens
217
Internal Database
217
Key Type and Length
217
Installing the Data Recovery Manager
218
Configuring Key Archival and Recovery Process
230
Step 1. Set up the Key Archival Process
230
Step 2. Set up the Key Recovery Process
236
Step 3. Test Your Key Archival and Recovery Setup
238
Chapter 7 Administrative Basics
243
The Administrative Interface
244
Netscape Administration Server
244
Netscape Console
245
The CMS Console
247
Setting up Certificate Authentication for the CMS Console
249
System Passwords
252
Password-Quality Checker
252
Passwords Stored by the Server
252
Starting, Stopping, and Restarting CMS Instances
254
Starting a Server Instance
254
Stopping a Server Instance
255
Restarting a Server Instance
256
Subsystem Configuration Overview
257
Configuring Multiple CMS Instances
257
Removing an Instance from a System
258
Mail Server
259
Configuration Files
259
Locating the Configuration File
259
Editing the Configuration File
260
Guidelines for Editing the Configuration File
261
Duplicating Configuration from One Instance to Another
263
Logs
263
About Logs
264
Services that Are Logged
266
Log Levels (Message Categories)
267
Buffered Versus Unbuffered Logging
268
Configuring Logs in the CMS Console
270
Configuring Logs in the Cms.cfg File
272
Monitoring Logs
274
Signing Log Files
275
Registering a Log Module
276
Deleting a Log Module
277
Signed Audit Log
277
Setting up Signed Audit Logs
280
Audit Logging Failures
281
Self Tests
282
Self Test Logging
282
Self Test Configuration
283
Modifying Self Test Configuration
283
Ports
285
About Ports
285
Changing a Port Number
288
Changing an IP Addresses
289
The Internal Database
290
About the Internal Database
290
Changing the Internal Database Configuration
291
Enable SSL Client Authentication with the Internal Database
292
Restricting Access to the Internal Database
293
Managing the Certificate Database
294
Viewing and Deleting Certificate Database Content
295
Changing the Trust Settings of a CA Certificate
296
Installing a New CA Certificate in the Certificate Database
297
Installing a CA Certificate Chain in the Certificate Database
298
Certificate Setup Wizard
298
Consideration When Getting New Certificates for the Subsystems
314
Tokens for Storing CMS Keys and Certificates
316
Internal Token
316
External Token
316
Managing Tokens Used by the Subsystems
319
Hardware Cryptographic Accelerators
320
Configuring the Server's Security Preferences
320
Configuring the Server to Use Separate SSL Server Certificates
321
Getting an SSL Client Certificate for a Subsystem
322
Chapter 8 Authorization
325
About Authorization
325
How Authorization Works
326
Default Groups
326
Setting up Administrators, Agents, and Auditors
330
Creating a User and Assigning Them to a Group
330
Storing a User's Certificate
331
Setting up Agents Using the Automated Process
332
Setting up a Trusted Manager
333
Agent Certificates
337
First Agent Certificate for a Certificate Manager
337
Getting an Agent's Certificate from a Public CA
339
Getting an Agent's Certificate from Certificate Management System
340
Revocation Status Checking of Agent Certificates
341
Modifying CMS User Entries
343
Changing a CMS User's Login Information
343
Changing a CMS User's Certificate
344
Changing Members in a Group
345
Deleting a CMS User
345
Creating a New Group
346
Authorization for CMS Users
347
Access Control Lists (Acls)
347
Access Control Instructions (Acis)
347
Changing Privileges
347
How Acis Are Formed
348
Editing Acls
350
ACL Reference
352
Certserver.acl.configuration
352
Certserver.admin.certificate
353
Certserver.admin.request.enrollment
353
Certserver.auth.configuration
353
Certserver.ca.certificate
354
Certserver.ca.certificates
355
Certserver.ca.configuration
355
Certserver.ca.connector
356
Certserver.ca.clone
356
Certserver.ca.crl
356
Certserver.ca.directory
357
Certserver.ca.group
357
Certserver.ca.ocsp
357
Certserver.ca.profiles
358
Certserver.ca.profile
358
Certserver.ca.requests
358
Certserver.ca.request.enrollment
359
Certserver.ca.request.profile
359
Certserver.ca.systemstatus
360
Certserver.ee.certificate
360
Certserver.ee.certificates
361
Certserver.ee.certchain
361
Certserver.ee.crl
361
Certserver.ee.profile
362
Certserver.ee.profiles
362
Certserver.ee.facetofaceenrollment
362
Certserver.ee.request.enrollment
363
Certserver.ee.request.facetofaceenrollment
363
Certserver.ee.request.ocsp
363
Certserver.ee.request.revocation
364
Certserver.ee.requeststatus
364
Certserver.general.configuration
364
Certserver.job.configuration
365
Certserver.kra.certificate.transport
366
Certserver.kra.configuration
366
Certserver.kra.connector
367
Certserver.kra.key
367
Certserver.kra.keys
367
Certserver.kra.request
368
Certserver.kra.requests
368
Certserver.kra.request.status
368
Certserver.kra.systemstatus
368
Certserver.log.configuration
369
Certserver.log.configuration.signedaudit.expirationtime
369
Certserver.log.configuration.filename
370
Certserver.log.content.signedaudit
370
Certserver.log.content
371
Certserver.ocsp.ca
371
Certserver.ocsp.cas
372
Certserver.ocsp.certificate
372
Certserver.ocsp.configuration
372
Certserver.ocsp.crl
373
Certserver.policy.configuration
373
Certserver.profile.configuration
374
Certserver.publisher.configuration
375
Certserver.ra.configuration
375
Certserver.ra.certificate
376
Certserver.ra.connector
376
Certserver.ra.facetofaceenrollment
377
Certserver.ra.facetofaceenrollment.enablehosts
377
Certserver.ra.group
377
Certserver.ra.profile
378
Certserver.ra.profiles
378
Certserver.ra.request.enrollment
378
Certserver.ra.request.profile
379
Certserver.ra.requests
379
Certserver.registry.configuration
380
Certserver.ra.systemstatus
380
Certserver.usrgrp.administration
381
Chapter 9 Authentication
383
Enrollment Overview
383
How Authentication Works
385
About Renewal
386
Dual-Key Pairs
386
Agent-Approved Enrollment
387
Setting up Agent-Approved Enrollment
387
Automated Enrollment
388
Setting up Directory Based Enrollment
389
Setting up NIS Based Enrollment
391
Setting up Pin Based Enrollment
395
Setting up Portal Enrollment
400
Setting up CMC Enrollment
404
Agent Initiated End User Enrollment
408
Setting up Agent Initiated Enrollment
408
Certificate-Based Enrollment
409
Setting up Certificate Based Enrollment
409
Issuing and Managing Server Certificates
411
Renewal of Server Certificates
412
Getting Certificates for Netscape Version 4.X and Later Servers
412
CEP Enrollment
414
About CEP Enrollment
414
Setting up Automated CEP Enrollment
415
Setting up Publishing of CEP Certificates and Crls
419
Certificate Issuance to Routers or VPN Clients
421
Example
423
Testing Your Enrollment Setup
425
Managing Authentication Plug-Ins
426
Generating Files Required by Third-Party Object Signing Tools
427
Chapter 10 Certificate Profiles
431
About Certificate Profiles
431
How Certificate Profiles Work
433
Setting up Certificate Profiles
434
Modifying a Certificate Profile
435
Certificate Profile Reference
442
Input Reference
445
Certificate Request Input
445
Dual Key Generation Input
446
Key Generation Input
446
Subject Name Input
446
Submitter Information Input
447
Output Reference
447
Certoutputimpl
447
Defaults Reference
448
Authority Info Access Extension Default
448
Authority Key Identifier Extension Default
450
Basic Constraints Extension Default
450
CRL Distribution Points Extension Default
452
Extended Key Usage Extension Default
453
Freshest CRL Extension Default
455
Key Usage Extension Default
456
Name Constraints Extension Default
458
Netscape Comment Extension Default
462
Netscape Certificate Type Extension Default
462
No Default Extension
464
OCSP no Check Extension Default
464
Policy Constraints Extension Default
464
Policy Mappers Extension Default
466
Signing Algorithm Default
467
Subject Alternative Name Extension Default
467
Subject Key Identifier Extension Default
469
Subject Name Default
470
Token Supplied Subject Name Default
470
User Supplied Extension Default
471
User Supplied Key Default
471
User Signing Algorithm Default
472
User Supplied Subject Name Default
472
User Supplied Validity Default
472
Validity Default
473
Constraints Reference
473
Basics Constraints Extension Constraint
473
Extended Key Usage Extension Constraint
474
Extension Constraint
475
Key Constraint
475
Key Usage Extension Constraint
475
No Constraint
477
Netscape Certificate Type Extension Constraint
477
Signing Algorithm Constraint
478
Subject Name Constraint
479
Validity Constraint
479
Chapter 11 Policies
481
Introduction to Policy
482
About Policy
482
Policy Rules
483
Policy Processor
484
Using Predicates in Policy Rules
485
Configuring Policy Rules for a Subsystem
491
Modifying Policy Rules
491
Deleting Policy Rules
492
Adding New Policy Rules
492
Reordering Policy Rules
493
Testing Policy Configuration
494
Using Javascript for Policies
495
Constraints-Specific Policy Module Reference
495
Attributepresentconstraints
495
Dsakeyconstraints
498
Issuerconstraints
499
Keyalgorithmconstraints
500
Renewalconstraints
501
Renewalvalidityconstraints
501
Revocationconstraints
502
Rsakeyconstraints
503
Signingalgorithmconstraints
504
Subcanameconstraints
505
Uniquesubjectnameconstraints
506
Validityconstraints
508
Extension-Specific Policy Module Reference
510
Authinfoaccessext
510
Authoritykeyidentifierext
513
Basicconstraintsext
514
Certificatepoliciesext
516
Certificaterenewalwindowext
517
Certificatescopeofuseext
519
Crldistributionpointsext
522
Extendedkeyusageext
524
Genericasn1Ext
527
Issueraltnameext
531
Keyusageext
535
Nameconstraintsext
541
Nsccommentext
548
Nscerttypeext
549
Ocspnocheckext
552
Policyconstraintsext
553
Policymappingsext
554
Privatekeyusageperiodext
556
Removebasicconstraintsext
557
Subjectaltnameext
557
Subjectdirectoryattributesext
561
Subjectkeyidentifierext
562
Managing Policy Plug-In Modules
563
Registering a Policy Module
564
Deleting a Policy Module
565
Chapter 12 Automated Notifications
567
About Automated Notifications
567
Setting up Automated Notifications
568
Types of Automated Notifications
568
Determining End-Entity Email Addresses
569
Setting up Automated Notifications
569
Configuring Specific Notifications by Editing the Configuration File
571
Testing Your Configuration
571
Customizing Notification Messages
572
Notification Message Templates
573
Token Definitions
575
Chapter 13 Automated Jobs
577
About Automated Jobs
577
Setting up Automated Jobs
578
Types of Automated Jobs
578
Setting up the Job Scheduler
579
Frequency Settings for Automated Jobs
579
Enabling and Configuring the Job Scheduler
580
Setting up Specific Jobs
581
Enabling and Configuring Specific Jobs Using the CMS Console
582
Enabling Configuring Specific Jobs by Editing the Configuration File
583
Configuration Parameters of Renewalnotificationjob
584
Configuration Parameters of Requestinqueuejob
586
Configuration Parameters of Unpublishexpiredjob
587
Customizing Notification Messages
589
Templates for Summary Notifications
589
Token Definitions
590
Managing Job Plug-Ins
592
Registering or Deleting a Job Module
592
Chapter 14 Revocation and Crls
593
Revocation
593
Authentication of End Users During Certificate Revocation
594
Certificate Revocation Forms
595
Cmcrevocation
596
Setting up CMC Revocation
596
Testing CMC Revoke
597
About Crls
598
Reasons for Revoking a Certificate
599
Revocation Checking by Netscape Servers
600
Publishing of Crls
600
CRL Issuing Points
601
Delta Crls
601
How Crls Work
601
Setting up the Issuance of Crls
603
Configuring Issuing Points
604
Configuring Crls for each Issuing Point
605
Setting CRL Extensions
607
CRL Extension Reference
608
Authoritykeyidentifier
608
Crlnumber
609
Crlreason
609
Deltacrlindicator
610
Freshestcrl
610
Holdinstruction
611
Invaliditydate
612
Issueralternativename
612
Issuingdistributionpoint
614
Chapter 15 Publishing
617
About Publishing
618
About Publishers
619
About Mappers
619
About Rules
619
About Publishing to Files
620
About LDAP Publishing
620
About OCSP Publishing
621
How Publishing Works
621
Setting up Publishing
622
Publishers
625
Configuring Publishers for Publishing to a File
625
Configuring Publishers for Publishing to OCSP
627
Configuring Publishers for LDAP Publishing
630
Publisher Plug-In Module Reference
630
Mappers
634
Configuring Mappers
634
Mapper Plug-In Modules Reference
637
Rules
646
Modifying Publishing Rules for Certificates and Crls
646
Rule Instance Reference
650
Enabling Publishing
653
Testing Publishing to Files
655
Configuring the Directory for LDAP Publishing
657
Schema
658
Entry for the CA
659
Bind DN
659
Directory Authentication Method
660
Updating Certificates and Crls in a Directory
660
Manually Updating Certificates in the Directory
661
Manually Updating the CRL in the Directory
662
Registering and Deleting Mapper and Publisher Plug-In Modules
663
Appendix A Common Criteria Environment: Security Requirements
665
Security Requirements for the IT Environment
665
Security Audit (FAU)
666
Cryptographic Support (FCS)
669
User Data Protection (FDP)
669
Identification and Authentication (FIA)
670
Security Management (FMT)
671
Protection of the TSF (FPT)
673
Trusted Path/Channels (FTP)
675
CIMC TOE Access Control Policy
675
Appendix B Common Criteria Environment: Setup and Operations
677
PKI Overview
677
Security Objectives
677
TOE Security Environment Assumptions
678
Security Requirements for the IT Environment
678
IT Environment Assumptions
678
Reliable Timestamp
678
Private and Secret Key Zeroization
678
Password and Certificate Storage
679
Hardware Token
679
Protection of Private and Secret Keys
679
Supported Operating Systems
680
Supported Browsers
680
CMS Privileged Users and Groups (Roles)
680
Drm
682
Ocsp
683
About Roles
683
CMS Common Criteria Environment Setup and Installation Guide
684
Understanding Setup of Common Criteria Evaluated Netscape CMS
684
CMS Common Criteria Environment Setup and Installation Process
684
Appendix C Understanding the Common Criteria Evaluated CMS Setup
687
Understanding the Common Criteria Environment
687
Secure Environment
687
CMS Roles Assignment
688
Who Needs to be Present
688
Understanding Operating System Setup (Users, Groups, and File Permissions)
688
Understanding CMS Installation
689
Configuring CMS to Use Hardware Tokens
689
Revocation Checking
689
SSL Client Authentication with the Internal Database
690
CMS Administrative Console
690
Backup and Restore of a CMS Subsystem
690
Common Criteria Deployment Scenarios
691
Features that Are Not Part of the Common Criteria Environment
691
Understanding Subsystem Setup
692
CMS Role Users and Authorization
692
Audit Logs
693
Certificate Profiles
693
Certificate Policies
694
Authentication
694
Crls
694
Jobs
694
Notifications
695
Publishing
695
Self Tests
695
Trust between Subsystems
695
Key Archival and Recovery
696
OCSP Responder Revocation Information Store
696
Common Criteria Environment Setup Procedures
696
Appendix D Common Criteria Environment: Security Objectives
697
1.1 Security Objectives for the TOE
697
1.1.1 Authorized Users
697
1.1.2 System
698
1.1.3 Cryptography
698
1.1.4 External Attacks
698
1.2 Security Objectives for the Environment
698
Non-IT Security Objectives for the Environment
699
1.2.2 IT Security Objectives for the Environment
701
Security Objectives for both the TOE and the Environment
701
Appendix E Common Criteria Environment: TOE Security Environment Assumptions
705
1.1 Secure Usage Assumptions
705
1.1.1 Personnel Assumptions
705
1.1.2 Physical Assumptions
707
1.1.3 Connectivity Assumptions
707
1.2 Threats
707
1.2.1 Authorized Users
707
1.2.2 System
708
1.2.3 Cryptography
708
1.2.4 External Attacks
709
1.3 Organization Security Policies
709
Appendix F Certificate Download Specification
711
Data Formats
711
Binary Formats
711
Text Formats
712
Importing Certificate Chains
713
Importing Certificates into Netscape Communicator
713
Importing Certificates into Netscape Servers
714
Object Identifiers
714
Appendix G Certificate and CRL Extensions
717
Introduction to Certificate Extensions
717
Structure of Certificate Extensions
719
Sample Certificate Extensions
721
Standard X.509 V3 Certificate Extensions
723
Introduction to CRL Extensions
734
Structure of CRL Extensions
735
Sample CRL and CRL Entry Extensions
736
Standard X.509 V3 CRL Extensions
737
Extensions for Crls
737
CRL Entry Extensions
740
Netscape-Defined Certificate Extensions
741
CA Certificates and Extension Interactions
742
Appendix H Object Identifiers
745
What's an Object Identifier
745
Registration of Object Identifiers
745
Appendix I Distinguished Names
747
What Is a Distinguished Name
747
Distinguished Name Components
748
Dns in Certificate Management System
750
Extending Attribute Support
752
Role of Distinguished Names in Certificates
757
Appendix J Introduction to Public-Key Cryptography
763
Internet Security Issues
763
Encryption and Decryption
765
Symmetric-Key Encryption
766
Public-Key Encryption
767
Key Length and Encryption Strength
768
Digital Signatures
769
Certificates and Authentication
770
A Certificate Identifies Someone or Something
771
Authentication Confirms an Identity
772
How Certificates Are Used
776
How CA Certificates Are Used to Establish Trust
784
Managing Certificates
790
Issuing Certificates
790
Certificates and the LDAP Directory
791
Key Management
791
Renewing and Revoking Certificates
792
Registration Authorities
793
Appendix K Introduction to SSL
795
The SSL Protocol
795
Ciphers Used with SSL
797
Man-In-The-Middle Attack
806
Advertisement
Netscape Certificate Management System 6.1 Manual (95 pages)
Brand:
Netscape
| Category:
Software
| Size: 0 MB
Table of Contents
Table of Contents
3
About this Guide
7
What You Should Know
7
Who Should Read this Guide
7
What's in this Guide
8
Conventions Used in this Guide
9
Documentation
11
Chapter 1 Agent Services
13
Overview of Certificate Management System
13
Agent Tasks
17
Certificate Manager Agent Services
17
Registration Manager Agent Services
19
Data Recovery Manager Agent Services
20
Online Certificate Status Manager Agent Services
21
Forms for Performing Agent Operations
22
Accessing Agent Services
25
Administrator/Agent Certificate Enrollment
25
Agent Services Entry Page
28
Services Summary Page
28
Chapter 2 Working with Certificate Profiles
29
About Certificate Profiles
29
How Certificate Profiles Work
31
Enabling and Disabling Certificate Profiles
32
Getting Certificate Profile Information
32
End User Certificate Profile
33
Policy Information
33
To Approve a Certificate Profile
33
To Disapprove a Certificate Profile
34
Chapter 3 Handling Certificate Requests
35
Managing Requests
35
Listing Certificate Requests
39
Selecting a Request
41
Approving Requests
42
Adjusting, Verifying, and Approving a Certificate Profile Request
43
Assigning a Request
44
Adjusting, Verifying, and Approving a Request
45
Other Options for Handling Requests
48
Sending an Issued Certificate to the Requester
49
Chapter 4 Finding and Revoking Certificates
53
Basic Certificate Listing
53
Advanced Certificate Search
55
Examining Certificates
60
Revoking Certificates
61
Searching for Certificates to Revoke
61
Revoking One or more Certificates
62
Revoking One Certificate
62
Revoking Multiple Certificates
63
Confirming a Revocation
63
Managing the Certificate Revocation List
65
Viewing or Examining Crls
65
Updating the CRL
66
Chapter 5 Publishing to a Directory
69
Working with a Directory Server
69
Automatic Directory Updates
69
Manual Directory Updates
70
Updating the Directory with Changes
70
Chapter 6 Recovering Encrypted Data
73
Finding and Recovering Keys
73
Finding Archived Keys
74
Selecting a Key
76
Recovering Keys
77
Remote Recovery Authorization
79
Viewing Key Service Requests
80
Listing Key Service Requests
81
Selecting a Request
82
Chapter 7 Managing OCSP Service Related Tasks
85
Listing Cas Identified by Online Certificate Status Manager
85
Identifying a CA to Online Certificate Status Manager
86
Adding a CRL to Online Certificate Status Manager
88
Checking the Revocation Status of a Certificate
90
Index
93
Netscape Certificate Management System 6.1 Manual (90 pages)
Command-line tools guide
Brand:
Netscape
| Category:
Software
| Size: 0 MB
Table of Contents
Table of Contents
3
About this Guide
7
What You Should Know
7
Who Should Read this Guide
7
What's in this Guide
8
Conventions Used in this Guide
9
Documentation
11
Chapter 1 Command-Line Tools
13
Chapter 2 CMS Upgrade Utility
19
Before Upgrading
20
Backing up Your Previous CMS Instance
20
Upgrading
20
After Upgrading
31
Chapter 3 Password Cache Utility
33
Location
33
Syntax
34
Usage
35
Listing the Contents of the Password Cache
35
Generating a New Protection Key for the Password Cache
36
Adding a New Entry to the Password Cache
37
Changing the Password of an Entry in the Password Cache
37
Deleting an Entry from the Password Cache
38
Chapter 4 Auditverify
39
About the Auditverify Tool
39
Setting up the Auditor's Database
39
Audit Verify Tool Syntax
40
Return Values
41
Using the Audit Verify Tool
41
Chapter 5 PIN Generator Tool
43
Locating the PIN Generator Tool
43
The Setpin Command
44
Command-Line Syntax
44
Example
49
How the Tool Works
49
Input File
51
Output File
53
How Pins Are Stored in the Directory
54
Exit Codes
54
Chapter 6 Extension Joiner Tool
57
Location
58
Syntax
58
Usage
58
Chapter 7 Backing up and Restoring Data
61
Backup and Restore Tools
61
Backing up Data
62
What the Backup Tool Does
63
What the Backup Tool Does Not Do
65
Running the Backup Tool
65
After You Finish a Backup
66
Signing Backup Data Using Cmsutil
67
Verifying Signed Backup Data Using Cmsutil
69
Restoring Data
70
Before You Restore Data
71
Running the Restore Tool
72
Chapter 8 ASCII to Binary Tool
77
Location
77
Syntax
77
Example
78
Chapter 9 Binary to ASCII Tool
79
Location
79
Syntax
79
Example
80
Chapter 10 Pretty Print Certificate Tool
81
Location
81
Syntax
81
Examples
82
Chapter 11 Pretty Print CRL Tool
85
Location
85
Syntax
85
Example
86
Index
89
Advertisement
Advertisement
Related Products
Netscape Certificate Management System 6.0
Netscape Certificate Management System 6.01
Netscape CERTIFICATE MANAGEMENT SYSTEM 7.0
Netscape Certificate Management System 6.2
Netscape NETSCAPE MANAGEMENT SYSTEM 4.5
Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 - AGENT GUIDE
Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 - COMMAND-LINE
Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 - CUSTOMIZATION GUIDE
Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 - PLUG-IN
Netscape NETSCAPE MANAGEMENT SYSTEM 6.0
Netscape Categories
Server
Software
Gateway
More Netscape Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL