Este contenido no está disponible en el idioma seleccionado.
9.6. Configuration for CMC
This section describes how to configure Certificate System for Certificate Management over CMS (CMC).
9.6.1. Understanding How CMC Works Copiar enlaceEnlace copiado en el portapapeles!
Copiar enlaceEnlace copiado en el portapapeles!
Before configuring CMC, read the following documentation to learn more about the subject:
- Requesting and Receiving Certificates Using CMC in the Certificate System Administration Guide (Common Criteria Edition).
- Making Rules for Issuing Certificates (Certificate Profiles) in the Certificate System Administration Guide (Common Criteria Edition).
9.6.2. Enabling the PopLinkWittnessV2 Feature Copiar enlaceEnlace copiado en el portapapeles!
Copiar enlaceEnlace copiado en el portapapeles!
For a high-level security on the Certificate Authority (CA), enable the following option in the
/var/lib/pki/instance_name/ca/conf/CS.cfg file:
cmc.popLinkWitnessRequired=true
cmc.popLinkWitnessRequired=true
9.6.4. Enabling CMCRevoke for the Web User Interface Copiar enlaceEnlace copiado en el portapapeles!
Copiar enlaceEnlace copiado en el portapapeles!
As described in the Performing a CMC Revocation section in the Red Hat Certificate System Administration Guide (Common Criteria Edition), there are two ways to submit CMC revocation requests.
In case when you use the
CMCRevoke utility to create revocation requests to be submitted through the web UI, add the following setting to the /var/lib/pki/instance_name/ca/conf/CS.cfg file:
cmc.bypassClientAuth=true
cmc.bypassClientAuth=true