
6 Netscape Enterprise Server Administrator’s Guide • April 2002 (Draft)
Chapter 5 SecuringYourEnterpriseServer ...................................... 87
RequiringAuthentication ............................................................... 88
UsingCertificatesforAuthentication................................................... 88
ServerAuthentication ............................................................. 88
ClientAuthentication.............................................................. 88
VirtualServerCertificates.......................................................... 89
CreatingaTrustDatabase ............................................................... 89
CreatingaTrustDatabase.......................................................... 89
Usingpassword.conf................................................................. 90
StartanSSL-enabledServerAutomatically ........................................... 91
Requesting and Installing a VeriSign Certificate ............................................ 91
RequestingaVeriSignCertificate ...................................................... 91
Installing a VeriSign Certificate . . . . . ................................................... 92
Requesting and Installing Other Server Certificates . ........................................ 92
RequiredCAInformation............................................................. 93
RequestingOtherServerCertificates ................................................... 94
Installing Other Server Certificates . . ................................................... 96
Installing a Certificate . . . .......................................................... 97
MigratingCertificatesWhenYouUpgrade ................................................ 99
MigratingaCertificate............................................................. 99
UsingtheBuilt-inRootCertificateModule ............................................. 100
ManagingCertificates ................................................................. 100
Installing and Managing CRLs and CKLs . . . . . . ........................................... 102
Installing a Local CRL or CKL . . . . . . .................................................. 102
ManagingLocalCRLsandCKLs ..................................................... 103
ConfiguringRemoteCRLs.............................................................. 104
ConfiguringAutomatic/RemoteCRLDownloads ...................................... 104
ReducingtheSSL3/TLSSessionCacheTimeout ..................................... 107
SettingSecurityPreferences ............................................................ 108
SSLandTLSProtocols .............................................................. 109
UsingSSLtoCommunicatewithLDAP ............................................... 109
EnablingSecurityforConnectionGroups .............................................. 110
TurningSecurityOn ............................................................. 110
SelectingaServerCertificateforaConnectionGroup ................................. 111
SelectingCiphers ................................................................ 112
ConfiguringSecurityGlobally........................................................ 114
SSLSessionTimeout .............................................................. 115
SSLCacheEntries................................................................. 115
SSL3SessionTimeout ............................................................. 115
UsingExternalEncryptionModules ..................................................... 115
Installing the PKCS#11 Module . . . . . .................................................. 116
UsingmodutiltoInstallaPKCS#11Module ......................................... 116
Usingpk12util................................................................... 117