
• Creating Client Certificate Automatically – having the guided procedure create a client
certificate for each CLIM automatically.
• Using your own X.509 Certificate – whereby you supply information so that OSM can use an
existing signed X.509 Certificate to each register CLIM.
After making your selection, click Continue to proceed to the step of the procedure, depending on
the option chosen.
Creating Client Certificate Automatically
Having chosen to create client certificates automatically, the Select Local CA dialog box is displayed
once again, this time showing a list of the Local CAs stored on the Key Manager cluster that are
in the Active state. From this list, select a trusted Local CA to be used to sign the client certificates
for each CLIM.
NOTE: The “Active” CAs displayed in this dialog box are the Local CAs known to the Key
Managers that will not expire for at least 31 days. To make sure you are selecting a Local CA that
is both “trusted” and has an expiration date suitable for the certificates you will create, log on to
a Key Manager interface and select the Security tab:
• To check expiration dates of the available Local CAs, click the Local CAs link located under
the “Certificates & CAs” heading in the left column of the page. Note that the client certificates
you create automatically through the OSM guided procedure will expire one day before the
expiration date of the Local CA used to sign them.
• After identifying a Local CA with a suitable expiration date, click the Trusted CA Lists link,
also located under the “Certificates & CAs” heading in the left column on the Security tab.
On that page, click Properties. If your Local CA of choice is not listed among the Trusted CAs,
click Edit and use the Add button to move the Local CA to the “Trusted CAs” list.
After selecting the desired Local CA in the Select Local CA dialog box, click Continue. The guided
procedure then displays the Create Client Certificate Automatically dialog box. It is populated with
the list of CLIMs to be registered (the list originally selected, minus any that failed any prior step
in the guided procedure). Select a certificate key size of either 1024 bit or 2048 bit, then click
the Create CLIM Client Certificates button to start the process of creating the client certificates.
NOTE: The default certificate key size is 1024 bit, but 2048 bit is required by ESKM 3.0.
302 Register CLIMs with Key Managers Guided Procedure Online Help
Comentarios a estos manuales