Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE Technical Information Seite 1

Stöbern Sie online oder laden Sie Technical Information nach Software Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE herunter. Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE System information Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 94
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 0
Red Hat Certificate System 7.3
System Agent Guide
7.3
ISBN: N/A
Publication date:
Seitenansicht 0
1 2 3 4 5 6 ... 93 94

Inhaltsverzeichnis

Seite 1 - System Agent Guide

Red Hat Certificate System 7.3System Agent Guide7.3ISBN: N/APublication date:

Seite 2

A warning indicates potential data loss, as may happen when tuning hardwarefor maximum performance.5. DocumentationThe Certificate System documentatio

Seite 3

Agent ServicesThis chapter describes the role of the privileged users, agents, in managing Certificate Systemsubsystems. It also introduces the tools

Seite 4

among one or more levels of subordinate CMs.Subsystems can also be cloned. All clones use the same keys and certificates as the master,which means tha

Seite 5

Token Processing System.The Token Processing System (TPS) acts as a registration authority for authenticating andprocessing smart card enrollment requ

Seite 6

Figure 2.1. The Certificate System and Users2. Agent TasksThe designated agents for each subsystem are responsible for the everyday management ofend e

Seite 7 - About This Guide

Data Recovery Manager AgentData Recovery Manager (DRM) agents initiate the recovery of lost keys and can obtaininformation about key service requests

Seite 8 - 4. Document Conventions

2.1. Certificate Manager Agent ServicesThe default entry page for (CM) agent services is shown in Figure 2.2, “Certificate ManagerAgent Services Page”

Seite 9 - Important

• Updates the CRL.The CM maintains a public list of revoked certificates, called the Certificate Revocation List(CRL). The list is usually maintained

Seite 10 - 5. Documentation

• Lists key recovery requests from end entities.• Lists or searches for archived keys.• Recovers private data-encryption keys.• Authorizes and approve

Seite 11 - Agent Services

• Identifies a CM to the OCSM.• Manually adds CRLs to the OCSM.• Submits requests for the revocation status of a certificate to the OCSM.For more info

Seite 12 - Token Key Service

This guide is for agents of Certificate System subsystems. It explains the different agentservices interfaces for the Certificate System subsystems an

Seite 13 - 1.2. Certificate System Users

• Edits token information.• Sets the token status.The TPS agent services page also has a tab to allow operations by TPS administrators.Figure 2.6. TPS

Seite 14 - 2. Agent Tasks

A subsystem agent with the correct certificates can access agent services forms through theagent services page to manage certificates. Table 2.1, “For

Seite 15

Form name (Operation) Subsystem Descriptionnewly issued certificates andupdated CRLs. Forinstructions on using thisform, see Section 2, “ManualDirecto

Seite 16

Form name (Operation) Subsystem DescriptionAuthorize Recovery DRM Authorize a key recoveryrequest remotely that wasinitiated by another DRMagent. For

Seite 17

Form name (Operation) Subsystem DescriptionSearch for Tokens TPS Search for tokens using eitherthe user ID of the user towhom the token was issued,or

Seite 18

9443, use the following URL to access the agent services interface:https://server.example.com:9443/ca/agent/caThere is also a services page for each s

Seite 20

CA: Working with Certificate ProfilesA Certificate Manager (CM) agent is responsible for approving certificate profiles that have beenconfigured by a

Seite 21

Approve the request.The certificate is issued, and the end entity then retrieves and uses it.Reject the request.No certificate is issued. The end enti

Seite 22

Profile ID Profile Name DescriptioncaSignedLogCert Manual Log SigningCertificate EnrollmentUsed to enrol audit logsigning certificatescaTPSCert Manual

Seite 23

Red Hat Certificate System 7.3: System Agent GuideCopyright © 2008 Red Hat, Inc.Copyright © 2008 Red Hat. This material may only be distributed subjec

Seite 24 - 4. Accessing Agent Services

Profile ID Profile Name Descriptionauthentication.caSimpleCMCUserCert Simple CMC Enrollment Request for User CertificateUsed to enrol user certificate

Seite 25

Profile ID Profile Name DescriptioncaDualRAuserCert RA Agent-Authenticated UserCertificate EnrollmentUsed to enrol user certificateswith RA agent auth

Seite 26

• Requester email The email address of the certificate requester.• Requester phone The phone number of the certificate requester.• Profile policy sets

Seite 27 - 1. About Certificate Profiles

Profile Policy Set Defaults Constraintsrequest. The default valuesare Criticality=false andOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4.userCertSet.8 - Su

Seite 28

agent can approve, and thus enable, a certificate profile. Once the certificate profile is enabled,it appears on the Certificate Profile tab of the en

Seite 29

which is linked to the Approve Certificate Profile page. This page lists information about thecertificate profile and allows an agent to approve a cer

Seite 30

profile. The certificate profile must first be disabled before an administrator to modify thecertificate profile.5.5. Disapproving a Certificate Profi

Seite 31 - 3.1. Example Profile

CA: Handling Certificate RequestsA Certificate Manager (CM) agent is responsible for handling both manual enrollment requestsmade by end entities (end

Seite 32 - 2.5.29.15) to the

action only checks the request but does not submit or edit the request.• Assign the request. A certificate request can be manually assigned by the age

Seite 33 - The keytype should be RSA

Figure 4.1. Certificate Request Management Process2. Listing Certificate RequestsThe CM keeps a queue of all certificate service requests that have be

Seite 34

Red Hat Certificate System 7.3

Seite 35 - 5.3. Policy Information

• Certificate enrollment requests• Certificate renewal requests• Certificate revocation requestsA CM agent must review and approve manual enrollment r

Seite 36

3.View certificate requests request type by selecting one of the options from the Request typemenu.• Show enrollment requests• Show renewal requests•

Seite 37 - 1. Managing Requests

Figure 4.3. Request Queue2.1. Selecting a RequestTo select a request from the queue, do the following:1. On the agent services page, click List Reques

Seite 38

Figure 4.4. Request DetailsNOTEIf the system changes the state of the displayed request, using the browser'sBack or Forward buttons or history to

Seite 39 - Listing Certificate Requests

• Completed• Canceled• Rejected• Any• Searching by Request Type. To search by the request type, select the Show requests thatare of type option, and s

Seite 40

3. Select the certificate request from the list.4. The certificate request details page contains several tables with information about therequest:• Re

Seite 41

generated and available to the user through the end entities page. If notifications have been set,then an email will be sent to the requester automati

Seite 42 - 2.1. Selecting a Request

Figure 4.5. A Newly Issued Certificate PageTo copy and mail a new server certificate to the requester, do the following:1. Create a new email addresse

Seite 43 - 2.2. Searching Requests

1. Open to the agent services page, click List Requests in the left frame, enter the serialnumber for the approved request, and click Find.2. In the R

Seite 44 - 3. Approving Requests

CA: Finding and RevokingCertificatesA Certificate Manager (CM) agent can use the agent services page to find a specific certificateissued by the Certi

Seite 45

1. About This Guide ... 11. Who Should Read This Guide

Seite 46

• To find a certificate with a specific serial number, enter the serial number in both the upperlimit and lower limit fields of the List Certificates

Seite 47 - -----END CERTIFICATE

Figure 5.2. Search Certificates3. To search by particular criteria, use one or more of the sections of the Search forCertificates form. To use a secti

Seite 48

• Status. Selects certificates by their status. A certificate has one of the following statuscodes:• Valid. A valid certificate has been issued, its v

Seite 49 - Certificates

• Basic Constraints. Shows CA certificates that are based on the Basic Constraintsextension.• Type. Lists certain types of certificates, such as all c

Seite 50

certificates matching the specified criteria that should be returned.Setting the number of certificates to be returned returns the first certificates

Seite 51 - 0x to indicate the

2. On the Search Results form, select a certificate to examine.If the desired certificate is not shown, scroll to the bottom of the list, specify an a

Seite 52

Only CM agents can revoke certificates other than their own. A certificate must be revoked ifone of the following situations occurs:• The owner of the

Seite 53 - ?) to match an

Figure 5.5. Revoke One or All Certificates4.2. Revoking One or More CertificatesAn entire list of certificates returned by a search can be revoked, or

Seite 54 - 3. Examining Certificates

1. On the CM's agent services page, click Revoke Certificates, specify search criteria, andclick Find to display a list of certificates.2. On the

Seite 55 - 4. Revoking Certificates

Figure 5.6. Confirm Certificate RevocationTo confirm the revocation, do the following:1. Inspect the details of the certificate to verify that it is t

Seite 56

5.2. Updating the CRL ...556. CA: Publishing to a Directory ...

Seite 57

• Key compromised• CA key compromised• Affiliation changed• Certificate superseded• Cessation of operation• Certificate is on hold4. Enter any additio

Seite 58

4. Choose how to display the CRL by selecting one of the options from the Display Type menu.The choices on this menu are as follows:• Cached CRL. View

Seite 59

Figure 5.7. Update Certificate Revocation List3. Select the algorithm to use to sign the new CRL. Before choosing an algorithm, make surethat any syst

Seite 60 - Completed; see

5. To update the CRL with the latest certificate revocation information, click Update.Updating the CRL57

Seite 62

CA: Publishing to a DirectoryA Red Hat Directory Server installation is required for the Certificate System subsystems to beinstalled; this directory

Seite 63 - Updating the CRL

NOTEAny client using a certificate is responsible for determining its validity by checkingthe expiration date against the client's current date i

Seite 64

DRM: Recovering Encrypted DataThis chapter describes how authorized Data Recovery Manager (DRM) agents process keyrecovery requests and recover stored

Seite 65 - CA: Publishing to a Directory

• Show completed requests. Completed requests include archival requests for which proof ofarchival has been sent and completed recovery requests.• Sho

Seite 66

In the old scheme, the password for the storage token was split and protected by individualrecovery agent passwords. This made it hard to access the s

Seite 67 - 1. List Requests

About This GuideThis guide describes the agent services interfaces used by Red Hat Certificate System agentsto administer subsystem certificates and k

Seite 68

Figure 7.1. Search for Keys Page3. To search by particular criteria, use the different sections of the Search for Keys or RecoverKeys form. To use a s

Seite 69 - 2.1. Finding Archived Keys

• Certificate. Finds the archived key that corresponds to a specific public key. Select thecheck box and paste the certificate containing the base-64

Seite 70

Figure 7.2. Search Results Page5. In the Search Results form, select a key.If a desired key is not shown, scroll to the bottom of the list and use the

Seite 71

To initiate key recovery, do the following:1. On the DRM agent services page, click Recover Keys, specify search criteria, and clickShow Key to displa

Seite 72 - 2.2. Recovering Keys

kra.noOfRequiredRecoveryAgents=1kra.recoveryAgentGroup=Data Recovery Manager Agents4. Set the PKCS #12 token password that the requester uses to impor

Seite 73 - CS.cfg file

11.Send the encrypted file to the requester.12.Give the recovery password to the requester in a secure manner.The requester must use this password to

Seite 75 - Recovering Keys

OCSP: Agent ServicesThis chapter describes how to perform Online Certificate Status Manager (OCSP) agent tasks,such as identifying a CA to the OCSP an

Seite 76

Figure 8.1. OCSP List Certificate Authorities Page2. Identifying a CA to the OCSPThe OCSP can be configured to receive CRLs from multiple CMs. Before

Seite 77 - OCSP: Agent Services

https://server.example.com:11443/ocsp/agent/ocsp9. In the left frame, click Add Certificate Authority.10.In the resulting form, paste the encoded CA s

Seite 78

requests and explains how to handle different aspects of certificate request management. ACM agent is responsible for handling requests by end entitie

Seite 79

The next page shows information about the CM that was added.NOTEIf the deployment contains chained CAs, such as a root CA and then severalsubordinate

Seite 80 - 3. Adding a CRL to the OCSP

https://server.example.com:11443/ocsp/agent/ocsp7. In the left frame, click Add Certificate Revocation List.8. In the resulting form, paste the encode

Seite 82

TPS: Agent ServicesThis chapter describes how to perform Token Processing System (TPS) agent tasks, such aslisting smart card tokens and resetting car

Seite 83 - TPS: Agent Services

• Listing activities associated with the tokens by the token CUID.• Searching activities by the token CUID.• Changing token status.Administrators can

Seite 84 - 3. Managing Tokens

Figure 9.1. Token Search ResultsClick the link associated with the token to display its details.Managing Tokens79

Seite 85 - Managing Tokens

Figure 9.2. Token DetailsFour operations can be performed on the token through this page:• Changing the token status.• Editing the token policy.Chapte

Seite 86 - Figure 9.2. Token Details

NOTEAgents can only modify the policy in effect for the token and add a new token.Administrators can also change the user ID of the owner and delete t

Seite 87 - 3.1. Changing Token Status

There are six possible token statuses:• The token is physically damaged.For this status, the TPS revokes the user certificates and marks the token los

Seite 88 - 3.2. Editing the Token

NoteIf the PIN_RESET policy is not set, then user-initiated PIN resets are allowed bydefault. If the policy is present and is changed from NO to YES,

Seite 89 - NO to YES, then a PIN reset

italic Courier fontItalic Courier font represents a variable, such as an installation directory:install_dir/bin/bold fontBold font represents applicat

Seite 90 - 3.5. Showing Token Activities

Through the TPS agent's page, however, viewing Token #1 shows Signing #1 is active; viewingToken #2 shows that Signing #1 is revoked. This is bec

Seite 91 - 6. Administrator Operations

Certificates.5. Searching Token ActivitiesThe token activities, such as enrollment, which are performed through the TPS subsystem canbe searched and l

Seite 92

Click Delete to remove the token, and all its associated certificates and user information, fromthe TPS database.Chapter 9. TPS: Agent Services86

Seite 93

IndexAaccessing end-entity gateways , 7accessing forms, 18agent services formsaccessing , 18Certificate Manager , 10Data Recovery Manager , 11Online C

Seite 94

overview , 6online certificate validation authoritydefined , 6PPKI (public-key infrastructure) , 5prerequisites , 1privileged operations and users , 9

Kommentare zu diesen Handbüchern

Keine Kommentare