McAfee MEJCAE-AM-DA Product Guide - Page 60

Updating X.509 certificates on your keyring, Configuration parameters, Updating keys on your keyring

Page 60 highlights

Working with X.509 Certificates Updating X.509 certificates on your keyring The following information appears: Signed Key : Scott Tibson Signed User ID: Scott Tibson Signed Key ID : 0x196DE730 (0xFBC4D3B5196DE730) Name: CN=Scott Tibson, [email protected], O=McAfee, OU=EBS Issuer: CN=Root CA, [email protected] Signer Key ID: 0xD7C74275 (0x03534DC9D7C74275) Type: X.509 Exportable: Yes Created: 2001-06-01 Expires: 2002-06-01 Last CRL: N/A Next CRL: N/A Serial Number: 9170E2A076CF0C8B4938 Trust Depth: 0 Updating X.509 certificates on your keyring To ensure that you are always using the most current keys belonging to other users, you should periodically update your local keyring with the keys on a key server. You can specify that all keys with X.509 signature certificates associated with them are also updated on your keyring. The CA-URL, CA-ROOT-CERT and CA-TYPE parameters must be set in the E-Business Server configuration file, or on the command line, in order to update X.509 certificates on your keyring. For instructions on how to set these parameters, see Configuration parameters on page 87. Once the above parameters are set, enter the following at the command line: ebs --key-update --x509 E-Business Server searches the key server for all keys on your local keyring and merges the matching keys back into your keyring. This ensures that any revocations from key servers are merged into the key. For details on how to update other key information, see Updating keys on your keyring on page 32. E-Business Server™ 8.6 Product Guide 58

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

E-Business Server
8.6
Product Guide
58
Working with X.509 Certificates
Updating X.509 certificates on your keyring
The following information appears:
Signed Key
: Scott Tibson <[email protected]>
Signed User ID: Scott Tibson <[email protected]>
Signed Key ID : 0x196DE730 (0xFBC4D3B5196DE730)
Updating X.509 certificates on your keyring
To ensure that you are always using the most current keys belonging to other users, you should periodically
update your local keyring with the keys on a key server. You can specify that all keys with X.509 signature
certificates associated with them are also updated on your keyring.
The
CA-URL
,
CA-ROOT-CERT
and
CA-TYPE
parameters must be set in the E-Business Server configuration file, or
on the command line, in order to update X.509 certificates on your keyring. For instructions on how to set
these parameters, see
Configuration parameters
on page 87
.
Once the above parameters are set, enter the following at the command line:
ebs --key-update --x509
E-Business Server searches the key server for all keys on your local keyring and merges the matching keys
back into your keyring. This ensures that any revocations from key servers are merged into the key.
For details on how to update other key information, see
Updating keys on your keyring
on page 32
.
Name:
CN=Scott Tibson, [email protected], O=McAfee, OU=EBS
Issuer:
CN=Root CA, [email protected]
Signer Key ID:
0xD7C74275 (0x03534DC9D7C74275)
Type:
X.509
Exportable:
Yes
Created:
2001-06-01
Expires:
2002-06-01
Last CRL:
N/A
Next CRL:
N/A
Serial Number:
9170E2A076CF0C8B4938
Trust Depth:
0