Este conteúdo não está disponível no idioma selecionado.
9.6. Configuration for CMC
This section describes how to configure Certificate System for Certificate Management over CMS (CMC).
9.6.1. Understanding How CMC Works Copiar o linkLink copiado para a área de transferência!
Copiar o linkLink copiado para a área de transferência!
Before configuring CMC, read the following documentation to learn more about the subject:
- Requesting and Receiving Certificates Using CMC in the Certificate System Administration Guide (Common Criteria Edition).
- Making Rules for Issuing Certificates (Certificate Profiles) in the Certificate System Administration Guide (Common Criteria Edition).
9.6.2. Enabling the PopLinkWittnessV2 Feature Copiar o linkLink copiado para a área de transferência!
Copiar o linkLink copiado para a área de transferência!
For a high-level security on the Certificate Authority (CA), enable the following option in the
/var/lib/pki/instance_name/ca/conf/CS.cfg file:
cmc.popLinkWitnessRequired=true
9.6.4. Enabling CMCRevoke for the Web User Interface Copiar o linkLink copiado para a área de transferência!
Copiar o linkLink copiado para a área de transferência!
As described in the Performing a CMC Revocation section in the Red Hat Certificate System Administration Guide (Common Criteria Edition), there are two ways to submit CMC revocation requests.
In case when you use the
CMCRevoke utility to create revocation requests to be submitted through the web UI, add the following setting to the /var/lib/pki/instance_name/ca/conf/CS.cfg file:
cmc.bypassClientAuth=true