22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

456 Lotus Security Handbook<br />

The Domino Registration Authority (RA) administrator is responsible for these<br />

tasks:<br />

► Register users, servers, and additional Notes certifiers.<br />

► Approve or deny Internet certificate requests.<br />

► Revoke certificates if they can no longer be trusted, such as if the subject of<br />

the certificate leaves the organization, or if the key has been compromised.<br />

Note: CAs and RAs must have at least Editor access to the master Domino<br />

Directory for the domain.<br />

Creating certifiers that use the CA process<br />

When you create a certifier specifically for the CA process, you must make sure<br />

that the CA process task is running on the server. Certifiers will not function if the<br />

CA process is not running. To manage the CA process, you use Tell commands<br />

at the server console.<br />

If the CA process task is running when you create a certifier, the process<br />

automatically adds newly-created certifiers when it refreshes, which takes place<br />

every 12 hours. However, the time period in which the Administration Requests<br />

database processes CA requests will vary. You can hasten the process by using<br />

Tell commands to have AdminP process all requests, and then refresh the CA<br />

process.<br />

Note: To load the CA task automatically, add the parameter ca to the Server<br />

setting in the NOTES.INI file.<br />

The general process for creating a CA-process enabled certifier is as follows:<br />

1. Migrate or create the certifier.<br />

– If you are creating a new Notes certifier, you must first register the O or<br />

OU level certifier and then migrate the certifier ID to the CA process.<br />

– If you have an existing Notes certifer, you must first migrate the certifier ID<br />

to the CA process.<br />

– If you have an existing Internet certifier, you must first migrate the key ring<br />

to the CA process.<br />

2. Configure the certifer.<br />

3. Add the certifier to the CA process.<br />

4. For Internet certifiers, create a Certificate Requests database.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!