Reflection PKI Services Manager User Guide
Total Page:16
File Type:pdf, Size:1020Kb
User Guide Reflection PKI Services Manager User Guide Reflection PKI Services Manager version 1.3.1 Copyrights and Notices Copyright © 2015 Attachmate Corporation. All rights reserved. No part of the documentation materials accompanying this Attachmate software product may be reproduced, transmitted, transcribed, or translated into any language, in any form by any means, without the written permission of Attachmate Corporation. Trademarks Attachmate, the Attachmate logo, and Reflection are registered trademarks of Attachmate Corporation in the USA. All other trademarks, trade names, or company names referenced in this product are used for identification only and are the property of their respective owners. Attachmate Corporation 705 5th Avenue South Seattle, WA 98104 USA +1.206.217.7100 http://www.attachmate.com (http://www.attachmate.com) Third-Party Notices This product contains software from third party suppliers. RSA (now EMC) - BSAFE Crypto-J This software includes RSA BSAFE cryptographic or security protocol software from RSA. Copyright © 2012 EMC Corporation. All rights reserved. EMC, RSA, the RSA logo, and BSAFE are registered trademarks of EMC Corporation in the United States and/or other countries. Used under private license. Additional third-party copyrights and notices, including license texts and other materials passed through in compliance with third party license terms, can be found in a thirdpartynotices.txt file in the program installation folder. Contents Reflection PKI Services Manager Features 5 1 Installing PKI Services Manager 7 System Requirements . 7 Windows Install and Uninstall. 7 Advanced Tab . 8 UNIX Install and Uninstall. 9 Upgrading From Earlier Versions . 10 PKI Services Manager Initialization . 11 2 Getting Started 13 PKI Services Manager Overview . 13 Configuration on Windows Systems . 14 Start and Stop the PKI Services Manager Service on Windows . 14 Configure PKI Services Manager on Windows . 15 Save, Reload, and Restart on Windows . 16 Check Validity and Mapping on Windows . 17 Configuration on UNIX Systems . 18 Start and Stop the Service on UNIX. 18 Configure PKI Services Manager on UNIX . 19 Save, Reload, and Restart on UNIX . 20 Check Validity and Mapping on UNIX . 21 3 Files and Application Data 23 Certificate Storage . 23 PKI Services Manager Public and Private Key . 24 PKI Services Manager Data Directories. 24 Change the Data Folder. 25 Windows Files . 26 UNIX Files . 27 4 PKI Services Manager Administration 29 Ensuring PKI Services Manager Availability . .29 Using a Server Cluster . 30 Configure a PKI Services Manager Cluster . 30 Configure Connections via a SOCKS Proxy . 32 Changing the JRE . 33 5 PKI Services Manager Console 37 Console Menu Commands. 37 Set Data Folder Dialog Box . 38 Test Certificate Dialog Box. 38 Public Key Details Dialog Box . 39 General Pane . 39 Contents 3 Local Store Pane . 41 Trusted Chain Pane . 42 Add Trust Anchor . .43 Local Store Browser. .43 Windows Certificate Browser. 43 Edit Trust Anchor . 44 Clone Trust Anchor . .44 Specify URI for Intermediate Certificate. 44 Revocation Pane . 45 Specify URI for CRL Server . 45 Specify URI for OCSP Responder . 46 Add OCSP Certificate . 46 Revocation Settings. .46 Identity Mapper Pane . 47 Add Mapper Rule. .48 Fetch Certificate. 50 6 Troubleshooting 53 Troubleshooting PKI Services Manager Configuration . 53 Troubleshooting Identity Mapping . 53 Logging . 54 7 Appendix 57 winpki and pkid Command Reference . .57 pkid_config Configuration File Reference . 60 pki_mapfile Map File Reference. 64 Sample Mapping Rules . 69 Sample Map File with RuleType Stanzas. .70 pki-client Command Line Utility . 70 PKI Services Manager Return Codes . .73 DOD PKI Information . ..