Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE Informazioni Techniche

Navigare online o scaricare Informazioni Techniche per Software Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE. Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE System information Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 94
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 0
Red Hat Certificate System 7.3
System Agent Guide
7.3
ISBN: N/A
Publication date:
Vedere la pagina 0
1 2 3 4 5 6 ... 93 94

Sommario

Pagina 1 - System Agent Guide

Red Hat Certificate System 7.3System Agent Guide7.3ISBN: N/APublication date:

Pagina 2

A warning indicates potential data loss, as may happen when tuning hardwarefor maximum performance.5. DocumentationThe Certificate System documentatio

Pagina 3

Agent ServicesThis chapter describes the role of the privileged users, agents, in managing Certificate Systemsubsystems. It also introduces the tools

Pagina 4

among one or more levels of subordinate CMs.Subsystems can also be cloned. All clones use the same keys and certificates as the master,which means tha

Pagina 5

Token Processing System.The Token Processing System (TPS) acts as a registration authority for authenticating andprocessing smart card enrollment requ

Pagina 6

Figure 2.1. The Certificate System and Users2. Agent TasksThe designated agents for each subsystem are responsible for the everyday management ofend e

Pagina 7 - About This Guide

Data Recovery Manager AgentData Recovery Manager (DRM) agents initiate the recovery of lost keys and can obtaininformation about key service requests

Pagina 8 - 4. Document Conventions

2.1. Certificate Manager Agent ServicesThe default entry page for (CM) agent services is shown in Figure 2.2, “Certificate ManagerAgent Services Page”

Pagina 9 - Important

• Updates the CRL.The CM maintains a public list of revoked certificates, called the Certificate Revocation List(CRL). The list is usually maintained

Pagina 10 - 5. Documentation

• Lists key recovery requests from end entities.• Lists or searches for archived keys.• Recovers private data-encryption keys.• Authorizes and approve

Pagina 11 - Agent Services

• Identifies a CM to the OCSM.• Manually adds CRLs to the OCSM.• Submits requests for the revocation status of a certificate to the OCSM.For more info

Pagina 12 - Token Key Service

This guide is for agents of Certificate System subsystems. It explains the different agentservices interfaces for the Certificate System subsystems an

Pagina 13 - 1.2. Certificate System Users

• Edits token information.• Sets the token status.The TPS agent services page also has a tab to allow operations by TPS administrators.Figure 2.6. TPS

Pagina 14 - 2. Agent Tasks

A subsystem agent with the correct certificates can access agent services forms through theagent services page to manage certificates. Table 2.1, “For

Pagina 15

Form name (Operation) Subsystem Descriptionnewly issued certificates andupdated CRLs. Forinstructions on using thisform, see Section 2, “ManualDirecto

Pagina 16

Form name (Operation) Subsystem DescriptionAuthorize Recovery DRM Authorize a key recoveryrequest remotely that wasinitiated by another DRMagent. For

Pagina 17

Form name (Operation) Subsystem DescriptionSearch for Tokens TPS Search for tokens using eitherthe user ID of the user towhom the token was issued,or

Pagina 18

9443, use the following URL to access the agent services interface:https://server.example.com:9443/ca/agent/caThere is also a services page for each s

Pagina 20

CA: Working with Certificate ProfilesA Certificate Manager (CM) agent is responsible for approving certificate profiles that have beenconfigured by a

Pagina 21

Approve the request.The certificate is issued, and the end entity then retrieves and uses it.Reject the request.No certificate is issued. The end enti

Pagina 22

Profile ID Profile Name DescriptioncaSignedLogCert Manual Log SigningCertificate EnrollmentUsed to enrol audit logsigning certificatescaTPSCert Manual

Pagina 23

Red Hat Certificate System 7.3: System Agent GuideCopyright © 2008 Red Hat, Inc.Copyright © 2008 Red Hat. This material may only be distributed subjec

Pagina 24 - 4. Accessing Agent Services

Profile ID Profile Name Descriptionauthentication.caSimpleCMCUserCert Simple CMC Enrollment Request for User CertificateUsed to enrol user certificate

Pagina 25

Profile ID Profile Name DescriptioncaDualRAuserCert RA Agent-Authenticated UserCertificate EnrollmentUsed to enrol user certificateswith RA agent auth

Pagina 26

• Requester email The email address of the certificate requester.• Requester phone The phone number of the certificate requester.• Profile policy sets

Pagina 27 - 1. About Certificate Profiles

Profile Policy Set Defaults Constraintsrequest. The default valuesare Criticality=false andOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4.userCertSet.8 - Su

Pagina 28

agent can approve, and thus enable, a certificate profile. Once the certificate profile is enabled,it appears on the Certificate Profile tab of the en

Pagina 29

which is linked to the Approve Certificate Profile page. This page lists information about thecertificate profile and allows an agent to approve a cer

Pagina 30

profile. The certificate profile must first be disabled before an administrator to modify thecertificate profile.5.5. Disapproving a Certificate Profi

Pagina 31 - 3.1. Example Profile

CA: Handling Certificate RequestsA Certificate Manager (CM) agent is responsible for handling both manual enrollment requestsmade by end entities (end

Pagina 32 - 2.5.29.15) to the

action only checks the request but does not submit or edit the request.• Assign the request. A certificate request can be manually assigned by the age

Pagina 33 - The keytype should be RSA

Figure 4.1. Certificate Request Management Process2. Listing Certificate RequestsThe CM keeps a queue of all certificate service requests that have be

Pagina 34

Red Hat Certificate System 7.3

Pagina 35 - 5.3. Policy Information

• Certificate enrollment requests• Certificate renewal requests• Certificate revocation requestsA CM agent must review and approve manual enrollment r

Pagina 36

3.View certificate requests request type by selecting one of the options from the Request typemenu.• Show enrollment requests• Show renewal requests•

Pagina 37 - 1. Managing Requests

Figure 4.3. Request Queue2.1. Selecting a RequestTo select a request from the queue, do the following:1. On the agent services page, click List Reques

Pagina 38

Figure 4.4. Request DetailsNOTEIf the system changes the state of the displayed request, using the browser'sBack or Forward buttons or history to

Pagina 39 - Listing Certificate Requests

• Completed• Canceled• Rejected• Any• Searching by Request Type. To search by the request type, select the Show requests thatare of type option, and s

Pagina 40

3. Select the certificate request from the list.4. The certificate request details page contains several tables with information about therequest:• Re

Pagina 41

generated and available to the user through the end entities page. If notifications have been set,then an email will be sent to the requester automati

Pagina 42 - 2.1. Selecting a Request

Figure 4.5. A Newly Issued Certificate PageTo copy and mail a new server certificate to the requester, do the following:1. Create a new email addresse

Pagina 43 - 2.2. Searching Requests

1. Open to the agent services page, click List Requests in the left frame, enter the serialnumber for the approved request, and click Find.2. In the R

Pagina 44 - 3. Approving Requests

CA: Finding and RevokingCertificatesA Certificate Manager (CM) agent can use the agent services page to find a specific certificateissued by the Certi

Pagina 45

1. About This Guide ... 11. Who Should Read This Guide

Pagina 46

• To find a certificate with a specific serial number, enter the serial number in both the upperlimit and lower limit fields of the List Certificates

Pagina 47 - -----END CERTIFICATE

Figure 5.2. Search Certificates3. To search by particular criteria, use one or more of the sections of the Search forCertificates form. To use a secti

Pagina 48

• Status. Selects certificates by their status. A certificate has one of the following statuscodes:• Valid. A valid certificate has been issued, its v

Pagina 49 - Certificates

• Basic Constraints. Shows CA certificates that are based on the Basic Constraintsextension.• Type. Lists certain types of certificates, such as all c

Pagina 50

certificates matching the specified criteria that should be returned.Setting the number of certificates to be returned returns the first certificates

Pagina 51 - 0x to indicate the

2. On the Search Results form, select a certificate to examine.If the desired certificate is not shown, scroll to the bottom of the list, specify an a

Pagina 52

Only CM agents can revoke certificates other than their own. A certificate must be revoked ifone of the following situations occurs:• The owner of the

Pagina 53 - ?) to match an

Figure 5.5. Revoke One or All Certificates4.2. Revoking One or More CertificatesAn entire list of certificates returned by a search can be revoked, or

Pagina 54 - 3. Examining Certificates

1. On the CM's agent services page, click Revoke Certificates, specify search criteria, andclick Find to display a list of certificates.2. On the

Pagina 55 - 4. Revoking Certificates

Figure 5.6. Confirm Certificate RevocationTo confirm the revocation, do the following:1. Inspect the details of the certificate to verify that it is t

Pagina 56

5.2. Updating the CRL ...556. CA: Publishing to a Directory ...

Pagina 57

• Key compromised• CA key compromised• Affiliation changed• Certificate superseded• Cessation of operation• Certificate is on hold4. Enter any additio

Pagina 58

4. Choose how to display the CRL by selecting one of the options from the Display Type menu.The choices on this menu are as follows:• Cached CRL. View

Pagina 59

Figure 5.7. Update Certificate Revocation List3. Select the algorithm to use to sign the new CRL. Before choosing an algorithm, make surethat any syst

Pagina 60 - Completed; see

5. To update the CRL with the latest certificate revocation information, click Update.Updating the CRL57

Pagina 62

CA: Publishing to a DirectoryA Red Hat Directory Server installation is required for the Certificate System subsystems to beinstalled; this directory

Pagina 63 - Updating the CRL

NOTEAny client using a certificate is responsible for determining its validity by checkingthe expiration date against the client's current date i

Pagina 64

DRM: Recovering Encrypted DataThis chapter describes how authorized Data Recovery Manager (DRM) agents process keyrecovery requests and recover stored

Pagina 65 - CA: Publishing to a Directory

• Show completed requests. Completed requests include archival requests for which proof ofarchival has been sent and completed recovery requests.• Sho

Pagina 66

In the old scheme, the password for the storage token was split and protected by individualrecovery agent passwords. This made it hard to access the s

Pagina 67 - 1. List Requests

About This GuideThis guide describes the agent services interfaces used by Red Hat Certificate System agentsto administer subsystem certificates and k

Pagina 68

Figure 7.1. Search for Keys Page3. To search by particular criteria, use the different sections of the Search for Keys or RecoverKeys form. To use a s

Pagina 69 - 2.1. Finding Archived Keys

• Certificate. Finds the archived key that corresponds to a specific public key. Select thecheck box and paste the certificate containing the base-64

Pagina 70

Figure 7.2. Search Results Page5. In the Search Results form, select a key.If a desired key is not shown, scroll to the bottom of the list and use the

Pagina 71

To initiate key recovery, do the following:1. On the DRM agent services page, click Recover Keys, specify search criteria, and clickShow Key to displa

Pagina 72 - 2.2. Recovering Keys

kra.noOfRequiredRecoveryAgents=1kra.recoveryAgentGroup=Data Recovery Manager Agents4. Set the PKCS #12 token password that the requester uses to impor

Pagina 73 - CS.cfg file

11.Send the encrypted file to the requester.12.Give the recovery password to the requester in a secure manner.The requester must use this password to

Pagina 75 - Recovering Keys

OCSP: Agent ServicesThis chapter describes how to perform Online Certificate Status Manager (OCSP) agent tasks,such as identifying a CA to the OCSP an

Pagina 76

Figure 8.1. OCSP List Certificate Authorities Page2. Identifying a CA to the OCSPThe OCSP can be configured to receive CRLs from multiple CMs. Before

Pagina 77 - OCSP: Agent Services

https://server.example.com:11443/ocsp/agent/ocsp9. In the left frame, click Add Certificate Authority.10.In the resulting form, paste the encoded CA s

Pagina 78

requests and explains how to handle different aspects of certificate request management. ACM agent is responsible for handling requests by end entitie

Pagina 79

The next page shows information about the CM that was added.NOTEIf the deployment contains chained CAs, such as a root CA and then severalsubordinate

Pagina 80 - 3. Adding a CRL to the OCSP

https://server.example.com:11443/ocsp/agent/ocsp7. In the left frame, click Add Certificate Revocation List.8. In the resulting form, paste the encode

Pagina 82

TPS: Agent ServicesThis chapter describes how to perform Token Processing System (TPS) agent tasks, such aslisting smart card tokens and resetting car

Pagina 83 - TPS: Agent Services

• Listing activities associated with the tokens by the token CUID.• Searching activities by the token CUID.• Changing token status.Administrators can

Pagina 84 - 3. Managing Tokens

Figure 9.1. Token Search ResultsClick the link associated with the token to display its details.Managing Tokens79

Pagina 85 - Managing Tokens

Figure 9.2. Token DetailsFour operations can be performed on the token through this page:• Changing the token status.• Editing the token policy.Chapte

Pagina 86 - Figure 9.2. Token Details

NOTEAgents can only modify the policy in effect for the token and add a new token.Administrators can also change the user ID of the owner and delete t

Pagina 87 - 3.1. Changing Token Status

There are six possible token statuses:• The token is physically damaged.For this status, the TPS revokes the user certificates and marks the token los

Pagina 88 - 3.2. Editing the Token

NoteIf the PIN_RESET policy is not set, then user-initiated PIN resets are allowed bydefault. If the policy is present and is changed from NO to YES,

Pagina 89 - NO to YES, then a PIN reset

italic Courier fontItalic Courier font represents a variable, such as an installation directory:install_dir/bin/bold fontBold font represents applicat

Pagina 90 - 3.5. Showing Token Activities

Through the TPS agent's page, however, viewing Token #1 shows Signing #1 is active; viewingToken #2 shows that Signing #1 is revoked. This is bec

Pagina 91 - 6. Administrator Operations

Certificates.5. Searching Token ActivitiesThe token activities, such as enrollment, which are performed through the TPS subsystem canbe searched and l

Pagina 92

Click Delete to remove the token, and all its associated certificates and user information, fromthe TPS database.Chapter 9. TPS: Agent Services86

Pagina 93

IndexAaccessing end-entity gateways , 7accessing forms, 18agent services formsaccessing , 18Certificate Manager , 10Data Recovery Manager , 11Online C

Pagina 94

overview , 6online certificate validation authoritydefined , 6PPKI (public-key infrastructure) , 5prerequisites , 1privileged operations and users , 9

Commenti su questo manuale

Nessun commento