LDAP-UX Client Services B.04.00 with Microsoft Windows 2000/2003 Active Directory Administrator's Guide

Installing LDAP-UX Client Services
Configuring the LDAP-UX Client Services with SSL Support
Chapter 252
The following steps show you an example on how to download the
Certificate Authority (CA) certificate from Windows 2000 Certificate
Authority Server using Netscape Communicator 4.75:
Step 1. Log in to your system as root.
Step 2. Use Netscape Communicator to connect to your Certificate Authority
Server. The following shows an example of using a link to connect to your
CA Server:
http://ADS servername/CertSrv
Step 3. Enter “administrator” as the usename and the user’s password for
Active Directory Server.
Step 4. Select a task, retrieve the CA certificate or certificate revocation list, in the
Microsoft Certificate Services screen. Then, click the Next button.
Step 5. Click the “Install this CA certificate link in the retrieve the CA certificate
or certificate revocation list window to allow your LDAP-UX client to
trust certificates issued from this Certificate Authority.
Step 6. Click the Next button in the window box which prompts that you are
about to go through the process of accessing a Certificate Authority. This
has serious implications on the security of future encrytions using
Netscape.
Step 7. Click the Next button in the window box which prompts that a CA
certifies the identity of . By accepting the CA, you will allow Netscape
Communicator to connect to and receive information from any site that it
certifies without prompting you or warning you.
Step 8. Click the Next button in the window box which prompts that here is the
certificate for this CA. Examine it carefully. The Certificate Fingeprint
can be used to verify that this authority is who they say they are.
Step 9. Check the “access the CA for certifying network sites”, “access
the CA for certifying e-mail users” and “access the CA for certifying
software developers” checkboxes in the new CA window screen.
Step 10. Click the Next button in the new CA box screen which prompts that by
accepting this CA, you have told Netscape Communicator to connect to
and receive information from any site that it certifies without warning
you or prompting you.