Datasheet
“main” (Installation and Administration) — 2004/6/25 — 13:29 — page 632 — #658
i
i
i
i
i
i
i
i
Note
You can select any storage location in the file system. This option
can also be used to save CA objects on a USB stack as transport
medium for example.
Note
Exporting Certificates to Floppy
YaST also allows certificates (but not CAs or CRLs) to be exported to a
floppy. The point of this option is the convenient transport of server cer-
tificates from an isolated CA computer to a server that should use these
certificates. This YaST function is the counterpart of a special YaST module
that only serves to import certificates exported in this way onto the server
(see the next section).
For floppy export, first enter the CA containing the certificates to export
and select ‘Certificates’. Select the required certificate in the list and export
it with ‘Export’ ➝ ‘Export to Floppy’. The next dialog asks you to insert
a floppy and enter the new PKCS12 password. After you click ‘Next’, the
certificate is written to the floppy.
Importing General Server Certificates
If you have exported a server certificate to floppy on an isolated CA man-
agement computer with YaST, you can import this certificate on a server as
a general server certificate. Do this during installation or at a later point with
the YaST module ‘Import General Server Certificate’ in the YaST control
center under ‘Security and Users’. The general server certificate is stored in
/etc/ssl/servercerts and can be used there by any CA-supported
service. When this certificate lapses, it can easily be replaced using the
same mechanisms. The only remaining administrative effort required is
the restart of the participating services.
After the module has been started, see the data for the current certificate in
the description field. For import, select ‘Import’ ➝ ‘From Floppy’ and insert
the appropriate floppy. After entering the certificate password and clicking
‘Next’, the certificate is imported then displayed in the description field.
632 26.1. X.509 Certification with YaST










