User guide
Chapter 8: Setting and Use of the Certificate/Key Management Environment Using the SMEE Command
8-6
3. Register the certificate and CRL.
− Register the certificate of the CA.
− Register the site certificate.
− Register the CRL.
For details of each command used hereafter, refer to the Reference Manual (Command Edition).
The executable files for the SMEE commands are stored in the following directory:
To set up the SSL environment, use the following commands:
• Create and set up a key management environment command for SMEE3 (makeslot maketoken)
Under <Windows® installation drive>:\Program Files\SecurecryptoLibraryR\Program\bin
• Others
Under <Windows® installation drive>:\Program Files\Common Files\Fujitsu Shared\F3FSSMEE
In the CORBA service, in order to execute with general user permission a CORBA application that uses
the SSL linkage function, perform Steps 1 to 3 with the same user permission as the CORBA application
user. If you set up an environment for certificate/key management using administrator permission, the
environment will not be accessible with general user permission and this will prevent the SSL Link function
from being used in the CORBA application.
If the certificate/key management environment is created with general user authority, the user who set up
the environment has authority to access the environment and use the SSL linkage function. In this case,
however, other general users do not have access authority for the environment. As a consequence, they
cannot use SSL linkage.
To allow multiple general users to use the SSL linkage function, the certificate/key management
environment access authority must be changed. Refer to“How to Use SSL with the CORBA Service” for
details of access authority.
Note
When you perform client attestation in Interstage HTTP Server, users other than super user authority need
to operate Procedure 1 to 3 (since it is necessary to set up the process of a Web server by consideration
on security except super user authority).
Moreover, this user and a group are set as the environmental definition file of Interstage HTTP Server.
Refer to Environment Setting of the Interstage HTTP Server regarding environment setup of Interstage
HTTP Server.