Manuals database logo
manualsdatabase
Your AI-powered manual search engine

Netscape NETSCAPE MANAGEMENT SYSTEM 4.5 manuals

NETSCAPE MANAGEMENT SYSTEM 4.5 first page preview

NETSCAPE MANAGEMENT SYSTEM 4.5

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. About This Guide
  7. What's in This Guide
  8. Conventions Used in This Guide
  9. Where to Go for Related Information
  10. Syntax
  11. Changing the Single Sign-On Password
  12. Adding a New Entry to the Password Cache
  13. Deleting an Entry From the Password Cache
  14. Creating a New Password Cache
  15. Location
  16. Usage
  17. Locating the PIN Generator Tool
  18. The setpin Command
  19. Example
  20. Input File
  21. Output File
  22. How PINs Are Stored in the Directory
  23. Exit Codes
  24. Chapter 5 Extension Joiner Tool
  25. Backing Up Data
  26. What the Backup Tool Does Not Do
  27. Running the Backup Tool
  28. After You Finish a Backup
  29. Restoring Data
  30. Running the Restore Tool
  31. Availability
  32. Options and Arguments
  33. Examples
  34. Listing Certificates in a Database
  35. Creating a Certificate
  36. Validating a Certificate
  37. Creating a Key Database
  38. Generating a New Key
  39. Displaying Public Key Information
  40. Introduction to Netscape Signing Tool
  41. What Is Netscape Signing Tool
  42. JAR Format and JAR Archives
  43. What Signing a File Means
  44. Using Netscape Signing Tool
  45. Getting Ready to Use Netscape Signing Tool
  46. Listing Available Certificates
  47. Signing a File
  48. Using Netscape Signing Tool with a ZIP Utility
  49. SignTool Syntax and Options
  50. Command File Syntax
  51. Generating Test Object-Signing Certificates
  52. Using Netscape Signing Tool with Smart Cards
  53. Using the -M Option to List Smart Cards
  54. Netscape Signing Tool and FIPS-140-1
  55. Verifying FIPS Mode
  56. Answers to Common Questions
  57. Description
  58. Options
  59. Example 1
  60. Example 2
  61. Example 3
  62. Example 4
  63. Usage Tips
  64. Restricting Ciphers
  65. JAR Installation File
  66. Script Grammar
  67. Keys
  68. Per-Platform Keys
  69. Per-File Keys
  70. Creating Database Files
  71. Setting a Default Provider
  72. Enabling a Slot
  73. Adding a Cryptographic Module
NETSCAPE MANAGEMENT SYSTEM 4.5 first page preview

NETSCAPE MANAGEMENT SYSTEM 4.5

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. Table Of Contents
  7. About This Guide
  8. Conventions Used in This Guide
  9. Where to Go for Related Information
  10. What You Need to Know to Change Forms
  11. HTTP, Query URLs, and HTML Forms
  12. Requests Sent to the CMS server
  13. Errors and the Error Template
  14. JavaScript Used By All Interfaces
  15. Part 1 Customizing End-Entity Services Interface
  16. How Client Type Determines the End-Entity Interface
  17. Accessing the End-Entity Services Interface
  18. Forms for Certificate Enrollment
  19. Forms for Certificate Renewal
  20. Forms for Certificate Revocation
  21. Forms for Key Recovery
  22. Output Templates for End-Entity Interfaces
  23. Overview of End-Entity Interfaces
  24. Certificate Enrollment Protocol Interface
  25. Challenge Revocation Interface
  26. Response
  27. Display Certificate From Request Interface
  28. Request Parameters
  29. Enrollment Interface
  30. Default Forms
  31. Get CA Chain Interface
  32. Get Certificate By Serial Number Interface
  33. Get Certificate From Request Interface
  34. Get CRL Interface
  35. List Certificates Interface
  36. Renewal Interface
  37. Revocation Interface
  38. Chapter 4 Internationalization of End-Entity Interface
  39. Part 2 Customizing Agent Services Interface
  40. Agent Services Interface
  41. Certificate Manager Agent Services
  42. Registration Manager Agent Services
  43. Data Recovery Manager Agent Services
  44. Agent Forms and Templates
  45. Locating Agent Forms and Templates
  46. Overview of Agent Interfaces
  47. Approve Revocation Interface
  48. Bulk Enrollment Interface
  49. Configuration Parameters
  50. Display Key By Serial Number Interface
  51. Display Key For Recovery Interface
  52. Examine Recovery Interface
  53. Get Approval Status Interface
  54. Get PKCS #12 Data Interface
  55. Grant Recovery Interface
  56. Key Query Interface
  57. Key Recovery Query Interface
  58. Process Certificate Request Interface
  59. Process DRM Request Interface
  60. Process Request Interface
  61. Recover Key By Serial Number Interface
  62. Remove Certificate Hold Interface
  63. Requests Query Interface
  64. Select for Revocation Interface
  65. Update CRL Interface
  66. Update Directory Interface
NETSCAPE MANAGEMENT SYSTEM 4.5 first page preview

NETSCAPE MANAGEMENT SYSTEM 4.5

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. Table Of Contents
  7. Table Of Contents
  8. About This Guide
  9. What You Should Already Know
  10. Conventions Used in This Guide
  11. Where to Go for Related Information
  12. Overview of Authentication Modules
  13. Manual Authentication
  14. UidPwdDirAuth Plug-in Module
  15. Configuration Parameters of UidPwdDirAuth
  16. UidPwdPinDirAuth Plug-in Module
  17. Configuration Parameters of UidPwdPinDirAuth
  18. NISAuth Plug-in Module
  19. Configuration Parameters of NISAuth
  20. PortalEnroll Plug-in Module
  21. Configuration Parameters of PortalAuth
  22. Certificate-Based Enrollment
  23. Enrollment Forms
  24. Customizing Enrollment Forms for Generating DSA Key Pairs
  25. Generating Files Required By Third-Party Object Signing Tools
  26. RenewalNotificationJob Plug-in Module
  27. Configuration Parameters of RenewalNotificationJob
  28. RequestInQJob Plug-in Module
  29. Configuration Parameters of RequestInQJob
  30. UnpublishExpiredJob Plug-in Module
  31. Configuration Parameters of UnpublishExpiredJob
  32. Schedule for Executing Jobs
  33. Customizing Notification Messages
  34. Customizing Message Templates
  35. Tokens for Request In Queue Notification Messages
  36. Overview of Constraints-Specific Policy Modules
  37. AttributePresentConstraints Plug-in Module
  38. Configuration Parameters of AttributePresentConstraints
  39. DSAKeyConstraints Plug-in Module
  40. Configuration Parameters of DSAKeyConstraints
  41. DSAKeyRule Rule
  42. Configuration Parameters of IssuerConstraints
  43. IssuerRule Rule
  44. KeyAlgorithmConstraints Plug-in Module
  45. KeyAlgRule Rule
  46. Configuration Parameters of RenewalConstraints
  47. RenewalConstraintsRule Rule
  48. RenewalValidityConstraints Plug-in Module
  49. Configuration Parameters of RenewalValidityConstraints
  50. DefaultRenewalValidityRule Rule
  51. RevocationConstraints Plug-in Module
  52. RevocationConstraintsRule Rule
  53. RSAKeyConstraints Plug-in Module
  54. RSAKeyRule Rule
  55. SigningAlgorithmConstraints Plug-in Module
  56. Configuration Parameters of SigningAlgorithmConstraints
  57. SigningAlgRule Rule
  58. Configuration Parameters of SubCANameConstraints
  59. SubCANameConstraints Rule
  60. UniqueSubjectNameConstraints Plug-in Module
  61. UniqueSubjectNameConstraints Rule
  62. Configuration Parameters of ValidityConstraints
  63. Overview of Extension-Specific Policy Modules
  64. AuthInfoAccessExt Plug-in Module
  65. Configuration Parameters of AuthInfoAccessExt
  66. AuthInfoAccessExt Rule
  67. AuthorityKeyIdentifierExt Plug-in Module
  68. Configuration Parameters of AuthorityKeyIdentifierExt
  69. AuthorityKeyIdentifierExt Rule
  70. Configuration Parameters of BasicConstraintsExt
  71. BasicConstraintsExt Rule
  72. CertificatePoliciesExt Plug-in Module
  73. Configuration Parameters of CertificatePoliciesExt
  74. CertificatePoliciesExt Rule
  75. CertificateRenewalWindowExt Plug-in Module
  76. Configuration Parameters of CertificateRenewalWindowExt
  77. CertificateScopeOfUseExt Plug-in Module
  78. Configuration Parameters of CertificateScopeOfUseExt
  79. CRLDistributionPointsExt Plug-in Module
  80. CRLDistributionPointsExt Rule
  81. ExtendedKeyUsageExt Plug-in Module
  82. Configuration Parameters of ExtendedKeyUsageExt
  83. CODESigningExt Rule
  84. OCSPSigningExt Rule
  85. GenericASN1Ext Plug-in Module
  86. Configuration Parameters of GenericASN1Ext
  87. GenericASN1Ext Rule
  88. Configuration Parameters of IssuerAltNameExt
  89. KeyUsageExt Plug-in Module
  90. Configuration Parameters of KeyUsageExt
  91. CMCertKeyUsageExt Rule
  92. RMCertKeyUsageExt Rule
  93. ServerCertKeyUsageExt Rule
  94. ClientCertKeyUsageExt Rule
  95. ObjSignCertKeyUsageExt Rule
  96. CRLSignCertKeyUsageExt
  97. Configuration Parameters of NameConstraintsExt
  98. NameConstraintsExt Rule
  99. NSCCommentExt Plug-in Module
  100. Configuration Parameters of NSCCommentExt
  101. NSCCommentExt Rule
  102. NSCertTypeExt Plug-in Module
  103. Configuration Parameters of NSCertTypeExt
  104. NSCertTypeExt Rule
  105. Configuration Parameters of OCSPNoCheckExt
  106. OCSPNoCheckExt Rule
  107. PolicyConstraintsExt Plug-in Module
  108. PolicyConstraintsExt Rule
  109. Configuration Parameters of PolicyMappingsExt
  110. PolicyMappingsExt Rule
  111. Configuration Parameters of PrivateKeyUsagePeriodExt
  112. RemoveBasicConstraintsExt Plug-in Module
  113. Configuration Parameters of RemoveBasicConstraintsExt
  114. SubjectAltNameExt Plug-in Module
  115. Configuration Parameters of SubjectAltNameExt
  116. SubjectAltNameExt Rule
  117. SubjectDirectoryAttributesExt Plug-in Module
  118. Configuration Parameters of SubjectDirectoryAttributesExt
  119. SubjectKeyIdentifierExt Plug-in Module
  120. Configuration Parameters of SubjectKeyIdentifierExt
  121. Overview of Mapper Modules
  122. LdapCaSimpleMap Plug-in Module
  123. Configuration Parameters of LdapCaSimpleMap
  124. LdapCaCertMap Mapper
  125. LdapCrlMap Mapper
  126. Configuration Parameters of LdapDNCompsMap
  127. LdapDNExactMap Plug-in Module
  128. Configuration Parameters of LdapDNExactMap
  129. Configuration Parameters of LdapSimpleMap
  130. LdapUserCertMap Mapper
  131. Configuration Parameters of LdapSubjAttrMap
  132. Overview of Publisher Modules
  133. FileBasedPublisher Plug-in Module
  134. LdapCaCertPublisher Plug-in Module
  135. Configuration Parameters of LdapCaCertPublisher
  136. LdapCaCertPublisher Publisher
  137. Configuration Parameters of LdapUserCertPublisher
  138. LdapUserCertPublisher Publisher
  139. Configuration Parameters of LdapCrlPublisher
  140. LdapCrlPublisher Publisher
  141. Overview of CRL Extension Modules
  142. AuthorityKeyIdentifier Rule
  143. CRLNumber Rule
  144. CRLReason Rule
  145. HoldInstruction Rule
  146. InvalidityDate Rule
  147. IssuerAlternativeName Rule
  148. Overview of Log Modules
  149. file Plug-in Module
  150. Configuration Parameters of file
  151. Audit Log Event Listener
  152. Error Log Event Listener
  153. System Log Event Listener
  154. Configuration Parameters of NTEventLog
  155. NTSystem Event Listener
  156. What Is a Distinguished Name
  157. Distinguished Name Components
  158. Root Distinguished Name
  159. DNs in Certificate Management System
  160. Extending Attribute Support
  161. Adding New or Proprietary Attributes
  162. Adding Attributes to an Enrollment Form
  163. Changing the DER Encoding Order
  164. Role of Distinguished Names in Certificates
  165. DNs in End-Entity Certificates
  166. Selecting DNs for Certificates
  167. Appendix B Object Identifiers
  168. Introduction to Certificate Extensions
  169. Structure of Certificate Extensions
  170. Sample Certificate Extensions
  171. Standard X.509 v3 Certificate Extensions
  172. authorityInfoAccess
  173. authorityKeyIdentifier
  174. basicConstraints
  175. certificatePolicies
  176. cRLDistributionPoints
  177. extKeyUsage
  178. issuerAltName
  179. keyUsage
  180. nameConstraints
  181. policyConstraints
  182. policyMappings
  183. privateKeyUsagePeriod
  184. subjectAltName
  185. subjectDirectoryAttributes
  186. subjectKeyIdentifier
  187. Introduction to CRL Extensions
  188. Sample CRL and CRL Entry Extensions
  189. Standard X.509 v3 CRL Extensions
  190. CRLNumber
  191. deltaCRLIndicator
  192. issuingDistributionPoint
  193. certificateIssuer
  194. invalidityDate
  195. Netscape-Defined Certificate Extensions
NETSCAPE MANAGEMENT SYSTEM 4.5 first page preview

NETSCAPE MANAGEMENT SYSTEM 4.5

Brand: Netscape | Category: Software
Table of contents
  1. Table Of Contents
  2. Table Of Contents
  3. Table Of Contents
  4. Table Of Contents
  5. Table Of Contents
  6. Table Of Contents
  7. Table Of Contents
  8. Table Of Contents
  9. Table Of Contents
  10. Table Of Contents
  11. Table Of Contents
  12. Table Of Contents
  13. Table Of Contents
  14. Table Of Contents
  15. Table Of Contents
  16. Table Of Contents
  17. Table Of Contents
  18. Table Of Contents
  19. Table Of Contents
  20. About This Guide
  21. What You Should Already Know
  22. Conventions Used in This Guide
  23. Where to Go for Related Information
  24. Part 1 Overview and Demo Installation
  25. Overview of Key Features
  26. Flexible end-entity registration services framework
  27. System Overview
  28. Public-Key Infrastructure
  29. CMS Subsystems or Managers
  30. Certificate Manager
  31. Registration Manager
  32. Data Recovery Manager
  33. Online Certificate Status Manager
  34. Basic System Configuration
  35. Plug-in Modules
  36. Policy Plug-in Modules
  37. Job Plug-In Modules
  38. Mapper and Publisher Plug-in Modules
  39. Event-Driven Notifications
  40. Command-Line Utilities
  41. Entry Points for Various Types of Users
  42. Agent Services Interface
  43. Registration Manager Agent Services
  44. Data Recovery Manager Agent Services
  45. Online Certificate Status Manager Agent Services Interface
  46. End-Entity Services Interface
  47. System Architecture
  48. JSS and the Java/JNI Layer
  49. Authentication and Policy Modules
  50. Security and Directory Protocols
  51. Some Enrollment Scenarios
  52. Extranet/E-Commerce: Acme Sales Corp
  53. Enrolling Existing Customers
  54. Enrolling New Customers
  55. Enrolling Extranet Users
  56. PIN Registration: Atlas Manufacturing
  57. VPN Client Enrollment and Revocation
  58. Router Enrollment and Revocation
  59. End Entities and Life-Cycle Management
  60. Access to Subsystems
  61. HTML Forms for End Users
  62. Netscape Personal Security Manager
  63. System Requirements
  64. Overview of the Default Demo
  65. Demo Passwords
  66. Installing the Default Demo
  67. Step 2. Run the Installation Wizard
  68. Step 3. Get the First User Certificate
  69. If You Need the First Agent Form Again
  70. Using the Default Demo
  71. Viewing Issued Certificates From the Agent Gateway
  72. Enrolling for a Certificate From the End-Entity Gateway
  73. Finding and Approving a Certificate Request
  74. Setting Your Browser to Use the Agent Certificate
  75. Create a Policy
  76. Use an LDAP Directory
  77. Step 1. Enable Directory-Based Authentication
  78. Step 2. Add a User to the Directory
  79. Step 3. Enroll with Directory-Based Authentication
  80. Publish Certificates to an LDAP Directory
  81. Configure the Publishing Destination
  82. Set Rules for Publishing Certificates
  83. Update the Publishing Directory
  84. Send Renewal Reminders
  85. Configuring a Mail Server for Certificate Management System
  86. Part 2 Planning and Installation
  87. Topology Decisions
  88. Single Certificate Manager
  89. Certificate Manager and Registration Manager
  90. Certificate Manager and Data Recovery Manager
  91. Certificate Manager, Data Recovery Manager, and Registration Manager
  92. Cloned Certificate Manager
  93. Certificate Authority Decisions
  94. CA Signing Key Type and Length
  95. CAs and Certificate Extensions
  96. CA Certificate Renewal or Reissuance
  97. Cryptographic Token Decisions
  98. Publishing to Certificates and CRLs to Files
  99. Publishing CRLs to the Online Certificate Status Manager
  100. Subsystem Certificate Decisions
  101. Registration Manager Certificates
  102. Data Recovery Manager Certificate and Storage Key
  103. Authentication Decisions
  104. Information for UNIX Installation Script
  105. User/Group Directory Server
  106. Administration Server Information
  107. Certificate Management System Identifier
  108. Configuration Directory Settings
  109. Administration Server Port
  110. Internal Database
  111. Remote Certificate Manager
  112. Network Configuration
  113. Key-Pair Information for CA Signing Certificate
  114. Validity Period for CA Signing Certificate
  115. CA Signing Certificate Request
  116. Registration Manager Configuration
  117. Subject Name for Registration Manager Signing Certificate
  118. Data Recovery Manager Configuration
  119. Subject Name for Transport Certificate
  120. Extensions for Transport Certificate
  121. Transport Certificate Request
  122. Online Certificate Status Manager Configuration
  123. Key-Pair Information for Online Certificate Status Manager Signing Certificate
  124. Online Certificate Status Manager Signing Certificate Issuer
  125. CA Signing Certificate
  126. SSL Server Key and Certificate
  127. Subject Name for SSL Server Certificate
  128. Extensions for SSL Server Certificate
  129. SSL Certificate Request
  130. Installation Overview
  131. Installation Stages
  132. Before You Begin the Installation
  133. Stage 1. Running the Installation Script
  134. Running the Installation Script on Windows NT
  135. Stage 2. Running the Installation Wizard
  136. Installing the Certificate Manager as a Root CA
  137. Installing the Certificate Manager as a Subordinate CA
  138. Installing a Standalone Registration Manager
  139. Installing a Standalone Data Recovery Manager
  140. Installing a Online Certificate Status Manager
  141. Stage 3. Enrolling for Administrator/Agent Certificate
  142. Agent Certificate for Other CMS Managers
  143. Stage 5. Creating Additional Instances or CA Clones
  144. Installing Multiple CMS Instances
  145. Cloning a Certificate Manager
  146. Step 1. Before You Begin
  147. Step 2. Create Instances for Clone CAs
  148. Installing Clone CA in a Different Server Group
  149. Installing Clone CA on a Separate Host
  150. Step 4. Copy Master CA's Certificate and Key Database
  151. Step 8. Establish Trust Between Master CA and Clone CAs
  152. Step A. Locate the Master CA's SSL Server Certificate
  153. Step B. Create a Privileged-User Entry for Clone CAs
  154. Step 9. Test Clone-Master Connection
  155. Step B. Approve the Request
  156. Step D. Revoke the Certificate
  157. Step 10. Use Master CA's Agent Certificate in Clone CAs
  158. Viewing Instance Information
  159. Changing the Name of an Instance
  160. Removing an Instance From a System
  161. Uninstalling From the Command Line
  162. Starting Certificate Management System
  163. Configuring the Server to Start Without the Single Sign-On Password
  164. Configuring the Server to Read the Single Sign-on Password From a File
  165. Starting From Netscape Console
  166. Starting From the Command Line
  167. Starting From the Windows NT Services Panel
  168. Stopping Certificate Management System
  169. Stopping From the Command Line
  170. Stopping From the Windows NT Services Panel
  171. Restarting From the Command Line
  172. Checking System Status
  173. Attending to an Unresponsive Server
  174. Password-Quality Checker
  175. Part 3 Configuration
  176. Netscape Console
  177. Users and Groups Tab
  178. Netscape Administration Server
  179. Starting Administration Server
  180. Shutting Down Administration Server
  181. The CMS Window
  182. Tasks Tab
  183. Logging In to the CMS Window
  184. Effects of Installation Type on Configuration
  185. Duplicating Configuration From One Instance to Another
  186. Locating the Configuration File
  187. Modifying the Configuration
  188. Guidelines for Editing the Configuration File
  189. Sample Configuration File
  190. Road Map to Configuring Subsystems
  191. Step 4. Set up Privileged Users
  192. Step 7: Enable Event-Driven Notifications
  193. Step 10. Set up Publishing
  194. Step 13. Plan for Backing up CMS Configuration and Data
  195. Chapter 11 Setting Up Ports
  196. Remote Administration Port
  197. Agent Port
  198. Step 1. Specify the Port Number
  199. Step 2: Specify IP Addresses
  200. Step 1. Identify the Directory Server Instance
  201. Step 2. Restrict Access to the Internal Database
  202. Privileged-User Types and Responsibilities
  203. Agents
  204. Agent's Certificate for SSL Client Authentication
  205. Revocation Status Checking of Agent Certificates
  206. Trusted Managers
  207. Subsystems That Can Function as Trusted Managers
  208. Connectors for Linking Trusted Managers
  209. Trusted Manager's Certificate for SSL Client Authentication
  210. Groups and Their Privileges
  211. Group for Administrators
  212. Groups for Agents
  213. Group for Data Recovery Manager Agents
  214. Group for Trusted Managers
  215. Setting Up Privileged Users
  216. Setting Up Agents
  217. Setting up Agents Using the Manual Process
  218. Setting Up Trusted Managers
  219. Setting Up a Registration Manager as a Trusted Manager
  220. Setting Up a Certificate Manager as a Trusted Manager
  221. Changing Privileged-User Information
  222. Changing a Privileged User's Certificate
  223. Changing Members in a Group
  224. Deleting a Privileged User
  225. Keys and Certificates for the Main Subsystems
  226. Certificate Manager's Key Pairs and Certificates
  227. wTLS CA Signing Certificate
  228. CRL Signing Key Pair and Certificate
  229. SSL Server Key Pair and Certificate
  230. Remote Administration Server Certificate
  231. Registration Manager's Key Pairs and Certificates
  232. Data Recovery Manager's Key Pairs and Certificates
  233. Transport Key Pair and Certificate
  234. Online Certificate Status Manager's Key Pairs and Certificates
  235. Tokens for Storing CMS Keys and Certificates
  236. Internal Token
  237. Managing Tokens Used by the Subsystems
  238. Changing a Token's Password
  239. Certificate Setup Wizard
  240. Using the Wizard to Request a Certificate
  241. Step 2. Choose the Certificate
  242. Step 3. Specify the Key-Pair Information
  243. Step 4. Specify the Subject Name for the Certificate
  244. Step 5. Specify the Validity Period
  245. Step 6. Specify Extensions
  246. Step 7. Copy the Certificate Signing Request
  247. Step 8. Check the Certificate Request Status
  248. Using the Wizard to Install a Certificate or Certificate Chain
  249. Data Formats for Installing Certificates and Certificate Chains
  250. Step 1. Select the Operation
  251. Step 2. Select the Certificate or Certificate Chain
  252. Step 3. Specify the Location of the Certificate
  253. Step 4. View the Certificate or Certificate Chain
  254. Step 6. Verify the Certificate Status
  255. Step 1. Get the Required SSL Server Certificates
  256. Getting an SSL Client Certificate for a Subsystem
  257. Setting Up Cipher Preferences for SSL Communications
  258. Configuring the Server to Use Specific Ciphers
  259. Getting New Certificates for the Subsystems
  260. Step 1. Plan for the New Certificate
  261. Step 2. Request the New Certificate
  262. Step 4. Deploy the New Certificate
  263. Deploying Registration Manager's Signing Certificate
  264. Deploying Data Recovery Manager's Transport Certificate
  265. Deploying a Subsystem's SSL Server Certificate
  266. Renewing Certificates for the Subsystems
  267. Step 1. Plan for Certificate Renewal
  268. Step 2. Renew the Existing Certificate
  269. Step 3. Install the Renewed Certificate
  270. Deploying Certificate Manager's Renewed CA Signing Certificate
  271. Deploying Data Recovery Manager's Renewed Transport Certificate
  272. Deploying a Subsystem's Renewed SSL Server Certificate
  273. Managing the Certificate Database
  274. Changing the Trust Settings of a CA Certificate
  275. Installing a New CA Certificate in the Certificate Database
  276. Installing a CA Certificate Chain in the Certificate Database
  277. Introduction to Authentication
  278. Privileged-User Authentication
  279. Authentication of Agents
  280. End-Entity Authentication
  281. Authentication of End Users During Certificate Revocation
  282. Configuring Authentication for End-User Enrollment
  283. Step 2. Set Up the Directory for PIN-Based Enrollment
  284. Step B. Update the Directory
  285. Step C. Prepare the Input File
  286. Step E. Check the Output File
  287. Step 4: Add an Authentication Instance
  288. Step 5. Set Up the Enrollment Interface
  289. Step B. Customize the Form
  290. Step D. Remove Unwanted Enrollment Options
  291. Step 6. Enable End-Entity Interaction
  292. Enabling End-Entity Interaction with a Registration Manager
  293. Step 7. Turn on Automated Notification
  294. Step 9. Deliver PINs to End Users
  295. Managing Authentication Plug-in Modules
  296. Deleting an Authentication Module
  297. Automated Notifications
  298. Notifications of Certificate Issuance to End Entities
  299. Notification of New Request in Queue
  300. Customizing Notification Messages
  301. Customizing Message Templates
  302. Tokens Available in Message Templates
  303. Tokens for Rejection Notifications to End Entities
  304. Tokens for Request In Queue Notification Messages
  305. Step 3. Turn on Request in Queue Notification
  306. Step 4. Verify Mail Server Settings
  307. Step 5. Test Your Configuration
  308. Configuring a Subsystem to Run Automated Jobs
  309. Step 2. Modify Existing Jobs
  310. Step 3. Delete Unwanted Jobs
  311. Step 5. Schedule the Frequency
  312. Step 7. Test Your Configuration
  313. Registering a Job Module
  314. Deleting a Job Module
  315. Introduction to Policy
  316. What Is Policy
  317. Policy Rules
  318. Using Predicates in Policy Rules
  319. Attributes for Predicates
  320. Policy Processor
  321. Configuring Policy Rules for a Subsystem
  322. Step 2. Modify Existing Policy Rules
  323. Step 3. Delete Unwanted Policy Rules
  324. Step 5. Reorder Policy Rules
  325. Step 6. Restart the Server
  326. Using JavaScript for Policies
  327. Deleting a Policy Module
  328. Publishing of Certificates to a Directory
  329. Timing of Directory Updates
  330. Directory Update Process
  331. Directory Synchronization
  332. What's a CRL
  333. Reasons for Revoking a Certificate
  334. Revocation Checking by Netscape Clients
  335. Publishing of CRLs to an LDAP Directory
  336. CRL Issuing Points
  337. Step 2. Set Up the Directory for Publishing
  338. Step C. Identify an Entry That Has Write Access
  339. Step E. Specify the Directory Authentication Method
  340. Step F. Modify the Certificate Mapping File
  341. Step G. Restart Directory Server
  342. Step B. Add Mappers, Publishers, and Publishing Rules
  343. Step 4. Configure the Certificate Manager to Publish CRLs
  344. Step A. Specify CRL Details
  345. Step B. Set the CRL Extensions
  346. Step C. Create a Mapper for the CRL
  347. Step D. Create a Publisher for the CRL
  348. Step E. Create a Publishing Rule for the CRL
  349. Step 5. Identify the Publishing Directory
  350. Step 6. Test Certificate and CRL Publishing
  351. Step A. Decide a Directory Entry for Requesting a Certificate
  352. Step D. Download the Certificate to the Browser
  353. Step G. Check the Directory for the CRL
  354. Manually Updating Certificates in the Directory
  355. Manually Updating the CRL in the Directory
  356. Configuring Certificate Manager to Publish to Files
  357. Step 2. Configure the Certificate Manager
  358. Step B. Create Publishing Rules for Certificates
  359. Step C. Create a Publishing Rule for CRLs
  360. Step D. Specify CRL Details
  361. Step E. Set the CRL Extensions
  362. Step F. Make Sure Publishing is Enabled
  363. Step D. Check the File for the Certificate
  364. Step E. Revoke the Certificate
  365. Step F. Check the File for the CRL
  366. Managing Mapper and Publisher Plug-in Modules
  367. Deleting a Mapper or Publisher Module
  368. What's an OCSP-Compliant PKI Setup
  369. How to Get an OCSP Responder
  370. How Online Certificate Status Manager Works
  371. How to Get OCSP-Compliant Clients
  372. Setting Up a Certificate Manager with OCSP Service
  373. Step 2. Install OCSP-Compliant Client
  374. Step 3. Enable Certificate Manager's HTTP Port
  375. Step 4. Enable Certificate Manager's OCSP Service
  376. Step 5. Configure Certificate Manager for Extensions
  377. Step 6. Restart the Certificate Manager
  378. Step 7. Test Your CA's OCSP Service Setup
  379. Step B. Request a Certificate
  380. Step E. Make Sure the CA is Trusted by the Browser
  381. Step F. Verify the Certificate in the Browser
  382. Step H. Revoke the Certificate
  383. Setting Up a Remote OCSP Responder
  384. Step 2. Install an OCSP-Compliant Client
  385. Step 3. Identify the CA to the OCSP Responder
  386. Step A. Specify CRL Format and Publishing Interval
  387. Step C. Create a Publisher for the CRL
  388. Step D. Create a Publishing Rule for the CRL
  389. Step E. Make Sure Publishing is Enabled
  390. Step 5. Configure Certificate Manager for Required Extension Policies
  391. Step 6. Configure the Online Certificate Status Manager
  392. Step 7. Restart the Certificate Manager
  393. Step 8. Restart the Online Certificate Status Manager
  394. Step 10. Test Your OCSP Responder Setup
  395. Step C. Approve the Request
  396. Step G. Check the Status of Online Certificate Status Manager
  397. Step I. Verify the Certificate in the Browser
  398. PKI Setup for Key Archival and Recovery
  399. Clients That Can Generate Dual Key Pairs
  400. Forms for Users and Key Recovery Agents
  401. Where the Keys are Stored
  402. How Key Archival Works
  403. Key Recovery Process
  404. Interface for the Key Recovery Process
  405. Local Versus Remote Key Recovery Authorization
  406. How Agent-Initiated Key Recovery Works
  407. Key Recovery Agent Scheme
  408. Changing Key Recovery Agents' Passwords
  409. Configuring Key Archival and Recovery Process
  410. Step A. Deploy Clients That Can Generate Dual Key Pairs
  411. Step C. Customize the Certificate Enrollment Form
  412. Step D. Configure Key Archival Policies
  413. Step 2. Set Up the Key Recovery Process
  414. Step B. Facilitate the Key Recovery Agents to Change the Passwords
  415. Step 3. Test Your Key Archival and Recovery Setup
  416. Step B. Verify the Key
  417. Step D. Restore the Key in the Browser's Database
  418. Introduction to Logs
  419. Logs Maintained by the Server
  420. Services That Are Logged
  421. Log Levels (Message Categories)
  422. Log File Locations
  423. Log File Naming Conventions
  424. Rotation of Log Files
  425. Location of Rotated Log Files
  426. Configuring CMS Logs
  427. Step 3. Delete Unwanted Listeners
  428. Step 4. Create New Listeners
  429. Monitoring CMS Logs
  430. Monitoring System Logs
  431. Monitoring Error Logs
  432. Monitoring Audit Logs
  433. Using System Tools for Monitoring the Server (Windows NT Only)
  434. Logging to Windows NT Event Log
  435. Archiving of Rotated Log Files
  436. Signing Log Files
  437. Managing Log Modules
  438. Deleting a Log Module
  439. Part 4 Issuing and Managing Certificates
  440. Certificate Issuance to Servers
  441. How the Manual Server Enrollment Process Works
  442. Getting Server SSL Certificates for Netscape Servers
  443. Step 1. Generate the Server Certificate Request
  444. Step 3. Install Your Server's SSL Certificate
  445. Step 5. Verify Your Server's SSL and CA Certificates
  446. Renewal of Server Certificates
  447. CEP Enrollment
  448. CEP Enrollment Using the Script
  449. Setting up CEP Enrollment Manually
  450. Step 1. Set up the Directory for Publishing Certificates and CRLs
  451. Step 2. Configure the Certificate Manager for Publishing Certificates and CRLs
  452. Step 3. Set Up Automated Enrollment
  453. Step 4. Set Up Multiple CEP Services
  454. Certificate Issuance to Routers or VPN Clients
  455. Step 2. Generate the Key Pair for the Router
  456. Step 3. Request the CA's Certificate
  457. Example
  458. Part 5 Appendix
Netscape categories
Server
Software
Gateway
More Netscape categories
Manuals database logo
manualsdatabase
Your AI-powered manual search engine