
8 Netscape Certificate Management System Installation and Setup Guide • March 2002
BeforeYouBegintheInstallation ..................................................... 213
Stage1.RunningtheInstallationScript................................................... 215
RunningtheInstallationScriptonUNIX............................................... 215
RunningtheInstallationScriptonWindowsNT ........................................ 218
Stage2.RunningtheInstallationWizard ................................................. 221
Installing the Certificate Manager as a Root CA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223
Installing the Certificate Manager as a Subordinate CA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226
Installing a Standalone Registration Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237
Installing a Standalone Data Recovery Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249
Installing a Online Certificate Status Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 260
Stage3.EnrollingforAdministrator/AgentCertificate ..................................... 271
AgentCertificateforaCertificateManager............................................. 271
AgentCertificateforOtherCMSManagers ............................................ 274
Stage4.FurtherConfigurationOptions .................................................. 277
Stage5.CreatingAdditionalInstancesorCAClones....................................... 278
Chapter 7 Installing and Uninstalling CMS Instances . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 279
Installing Multiple CMS Instances . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 280
CloningaCertificateManager .......................................................... 282
Step1.BeforeYouBegin............................................................. 283
Step2.CreateInstancesforCloneCAs ................................................ 285
Installing Clone CA in Master CA’s Server Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285
Installing Clone CA in a Different Server Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 286
Installing Clone CA on a Separate Host . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 287
Step3.ShutdowntheMasterCA ..................................................... 287
Step4.CopyMasterCA’sCertificateandKeyDatabase ................................. 288
Step5.StarttheMasterCA .......................................................... 288
Step6.ConfiguretheCloneCA ...................................................... 289
Step8.EstablishTrustBetweenMasterCAandCloneCAs............................... 290
StepA.LocatetheMasterCA’sSSLServerCertificate................................. 290
StepB.CreateaPrivileged-UserEntryforCloneCAs ................................. 292
Step9.TestClone-MasterConnection ................................................. 295
StepA.RequestaCertificatefromtheCloneCA ..................................... 295
StepB.ApprovetheRequest ...................................................... 296
StepC.DownloadtheCertificatetotheBrowser ..................................... 296
StepD.RevoketheCertificate ..................................................... 297
StepE.CheckMasterCA’sCRLfortheRevokedCertificate ........................... 297
Step10.UseMasterCA’sAgentCertificateinCloneCAs ................................ 298
ViewingInstanceInformation .......................................................... 299
ChangingtheNameofanInstance ...................................................... 301
RemovinganInstanceFromaSystem.................................................... 302
UninstallingCertificateManagementSystem ............................................. 303
UninstallingFromtheCommandLine ................................................ 303