McAfee MEJCAE-AM-DA Product Guide - Page 101

Interactive, Issuer-dn, Default Value, Issuer-serial, Keyserver, Notes, Keyserver-type, Key-size

Page 101 highlights

Using the Configuration File Learning about the configuration file INTERACTIVE The INTERACTIVE parameter is only supported for compatibility purposes. A warning appears if your configuration file contains this setting. ISSUER-DN Specifies the default root certificate to use when issuing an X.509 certificate. This certificate must be a self-signed X.509 certificate. The ISSUER-DN option is used for --key-sign --x509 operations. This is NEVER used for --cert-request or --cert-retrieve operations. The DN specifies the certificate that is used by the issuer of the new X.509 certificate and is placed in the new X.509 certificate. A key may have more than one X.509 certificate attached to it; therefore, you must also specify the ISSUER-SERIAL to uniquely identify the certificate you want to use to issue new certs. The certificate specified must be a self-signed X.509 certificate. Default Value ISSUER-DN = "" ISSUER-SERIAL Use in conjunction with the ISSUER-DN option to uniquely identify the default root certificate to use for key signing. For more information, see ISSUER-DN Default Value ISSUER-SERIAL = "" KEYSERVER Specifies the URL of the default key server. The key server specified by the KEYSERVER parameter will be used for any operations involving the key server. You can also set a key server URL on the command line by specifying --keyserver. Notes The default keyserver is ldap://keyserver.pgp.com. The URL may be in any of the following formats: ldap://, ldaps://, or http://URL. If no method is specified, then ldap:// is assumed. The default ports (389, 636 and 11371 respectively) are assumed if no port number is specified. If the key server is not an E-Business Server key server, then use --keyserver-type to set the type of server you are using. KEYSERVER-TYPE This parameter specifies the type of key server being used during key server operations. Default Value KEYSERVER-TYPE = PGP Values are as follows: • PGP. Use this option if the server you are connecting to is the E-Business Server Keyserver via LDAP, LDAPS, HTTP, or for interfacing with other HTTP key servers. • LDAPPGP. Use this option if the server you are connecting to is an LDAP or LDAPS server, such as the Netscape Directory Server. • LDAPX509. Use this option if the server you are connecting to is an LDAP-based X.509 server, such as Microsoft's Directory Server. KEY-SIZE This parameter sets the default key size used during key generation. 99 E-Business Server™ 8.6 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

99
E-Business Server
8.6
Product Guide
Using the Configuration File
Learning about the configuration file
INTERACTIVE
The
INTERACTIVE
parameter is only supported for compatibility purposes. A warning appears if your
configuration file contains this setting.
ISSUER-DN
Specifies the default root certificate to use when issuing an X.509 certificate. This certificate must be a
self-signed X.509 certificate. The
ISSUER-DN
option is used for
--key-sign --x509
operations. This is NEVER
used for
--cert-request
or
--cert-retrieve
operations.
The DN specifies the certificate that is used by the issuer of the new X.509 certificate and is placed in the
new X.509 certificate.
A key may have more than one X.509 certificate attached to it; therefore, you must also specify the
ISSUER-SERIAL
to uniquely identify the certificate you want to use to issue new certs.
The certificate specified must be a self-signed X.509 certificate.
Default Value
ISSUER-DN = ""
ISSUER-SERIAL
Use in conjunction with the
ISSUER-DN
option to uniquely identify the default root certificate to use for key
signing. For more information, see
ISSUER-DN
Default Value
ISSUER-SERIAL = ""
KEYSERVER
Specifies the URL of the default key server. The key server specified by the
KEYSERVER
parameter will be used
for any operations involving the key server. You can also set a key server URL on the command line by
specifying
--keyserver
.
Notes
The default keyserver is
ldap://keyserver.pgp.com
.
The URL may be in any of the following formats:
ldap://
,
ldaps://
, or
http://URL
. If no method is specified,
then
ldap://
is assumed. The default ports (389, 636 and 11371 respectively) are assumed if no port number
is specified.
If the key server is not an E-Business Server key server, then use
--keyserver-type
to set the type of server
you are using.
KEYSERVER-TYPE
This parameter specifies the type of key server being used during key server operations.
Default Value
KEYSERVER-TYPE = PGP
Values are as follows:
PGP
. Use this option if the server you are connecting to is the E-Business Server Keyserver via LDAP,
LDAPS, HTTP, or for interfacing with other HTTP key servers.
LDAPPGP
. Use this option if the server you are connecting to is an LDAP or LDAPS server, such as the
Netscape Directory Server.
LDAPX509
. Use this option if the server you are connecting to is an LDAP-based X.509 server, such as
Microsoft’s Directory Server.
KEY-SIZE
This parameter sets the default key size used during key generation.