McAfee MEJCAE-AM-DA Product Guide - Page 55

Retrieving and adding the Root CA certificate to your keyring

Page 55 highlights

Working with X.509 Certificates Getting an X.509 certificate from a CA 2 Enter information about the CA in the E-Business Server configuration file (see Specifying CA parameters in the E-Business Server configuration file on page 53). 3 Request a certificate from the CA. Your X.509 certificate request is verified and signed by the CA (see Automatically requesting a certificate from the CA on page 53). (The CA's signature on the certificate makes it possible to detect any subsequent tampering with the identifying information or the public key, and it implies that the CA considers the information in the certificate valid.) 4 Retrieve the certificate issued by the CA and add it to your key pair (see Retrieve your certificate and add it to your key pair on page 54). Retrieving and adding the Root CA certificate to your keyring Whether you are automatically requesting or manually requesting X.509 certificates to add to your keys, you must first obtain and add the Root CA certificate to your keyring. The only exception is if you are requesting a PKCS #10 certificate. Note: When you add or change information in your key pair, always update it on the key server so that your most current key can be available to anyone. See Adding your key to a key server on page 26 for instructions. To retrieve and add the Root CA certificate to your keyring: 1 Open your Web browser and connect to the CA's enrollment site. 2 Locate and examine the Root CA certificate. This process varies between Certificate Authorities. For example, if your company were using the Net Tools PKI Server, you would click the Download a CA Certificate link, and then click the Examine this Certificate button. 3 Copy the key block for the Root CA certificate and paste it into a file. 4 Add the Root CA certificate to your keyring. See Adding an X.509 certificate to your key or keyring on page 52 for instructions. Specifying CA parameters in the E-Business Server configuration file Specify the CA's URL using the CA-URL parameter. This URL must be fully qualified. For example, you might enter something like https://myca.ebs.com:444 (this is the same URL you used to retrieve the Root CA). If there is a separate URL for retrieving certificate revocation lists (CRLs), specify it using the CA-REVOCATION-URL parameter. If you do not know the URL for revocation, leave this option blank. Specify the name of certificate authority you are using with the CA-TYPE option. Your choices are: • nettools (Net Tools PKI) • verisign (VeriSign OnSite) • entrust (Entrust) • iplanet (iPlanet CMS) • win2k (Windows 2000) Specify the Root CA certificate you retrieved earlier using the CA-ROOT-CERT parameter. For more information on retrieving the Root CA certificate, see Retrieving and adding the Root CA certificate to your keyring on page 53. Automatically requesting a certificate from the CA After specifying CA parameters in the configuration file (see Specifying CA parameters in the E-Business Server configuration file on page 53), use the --cert-request option to automatically request a certificate from the CA. You can request that specific attributes be added to your new certificate using the --cert-attribute option. It is up to the CA's discretion whether or not they include these attributes. For more information on adding certificate attributes, see Specifying certificate attributes on page 51. To request a certificate: 53 E-Business Server™ 8.6 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

53
E-Business Server
8.6
Product Guide
Working with X.509 Certificates
Getting an X.509 certificate from a CA
2
Enter information about the CA in the E-Business Server configuration file
(see
Specifying CA parameters
in the E-Business Server configuration file
on page 53
).
3
Request a certificate from the CA. Your X.509 certificate request is verified and signed by the CA (see
Automatically requesting a certificate from the CA
on page 53
). (The CA’s signature on the certificate
makes it possible to detect any subsequent tampering with the identifying information or the public key,
and it implies that the CA considers the information in the certificate valid.)
4
Retrieve the certificate issued by the CA and add it to your key pair (see
Retrieve your certificate and add
it to your key pair
on page 54
).
Retrieving and adding the Root CA certificate to your keyring
Whether you are automatically requesting or manually requesting X.509 certificates to add to your keys, you
must first obtain and add the Root CA certificate to your keyring. The only exception is if you are requesting
a PKCS #10 certificate.
Note:
When you add or change information in your key pair, always update it on the key server so that your most current
key can be available to anyone. See
Adding your key to a key server
on page 26
for instructions.
To retrieve and add the Root CA certificate to your keyring:
1
Open your Web browser and connect to the CA’s enrollment site.
2
Locate and examine the Root CA certificate. This process varies between Certificate Authorities. For
example, if your company were using the Net Tools PKI Server, you would click the
Download a CA
Certificate link
, and then click the
Examine this Certificate
button.
3
Copy the key block for the Root CA certificate and paste it into a file.
4
Add the Root CA certificate to your keyring. See
Adding an X.509 certificate to your key or keyring
on
page 52
for instructions.
Specifying CA parameters in the E-Business Server configuration file
Specify the CA’s URL using the
CA-URL
parameter. This URL must be fully qualified. For example, you might
enter something like https://myca.ebs.com:444 (this is the same URL you used to retrieve the Root CA).
If there is a separate URL for retrieving certificate revocation lists (CRLs), specify it using the
CA-REVOCATION-URL
parameter. If you do not know the URL for revocation, leave this option blank.
Specify the name of certificate authority you are using with the
CA-TYPE
option. Your choices are:
nettools
(Net Tools PKI)
verisign
(VeriSign OnSite)
entrust
(Entrust)
iplanet
(iPlanet CMS)
win2k
(Windows 2000)
Specify the Root CA certificate you retrieved earlier using the
CA-ROOT-CERT
parameter. For more information
on retrieving the Root CA certificate, see
Retrieving and adding the Root CA certificate to your keyring
on
page 53
.
Automatically requesting a certificate from the CA
After specifying CA parameters in the configuration file (see
Specifying CA parameters in the E-Business
Server configuration file
on page 53
), use the
--cert-request
option to automatically request a certificate
from the CA.
You can request that specific attributes be added to your new certificate using the
--cert-attribute
option.
It is up to the CA’s discretion whether or not they include these attributes. For more information on adding
certificate attributes, see
Specifying certificate attributes on page 51
.
To request a certificate: