Apple 10.6 Server User Manual


 
Using a CA to Create a Certicate for Someone Else
You can use your CA certicate to issue a certicate to someone else. By doing so you
are stating you want to be a trusted party that can certify the identity of the certicate
holder.
Before you can create a certicate for someone, that person must generate a CSR. The
user can use the Certicate Assistant to generate the CSR and mail the request to you.
You then use the CSR’s text to make the certicate.
To create a certicate for someone else:
1 Start Keychain Access.
Keychain Access is found in the /Applications/Utilities/ directory.
2 In the Keychain Access menu, select Certicate Assistant > Create a Certicate for
Someone Else as a Certicate Signing Authority.
The Certicate Assistant starts, and guides you through the process of making the
certicate.
3 Drag the CSR and drop it on the target area.
4 Choose the CA that is the issuer and sign the request.
You can choose to override the request defaults.
5 Click Continue.
If you override the request defaults, provide the Certicate Assistant with the
requested information and click Continue.
The Certicate is now signed. The default mail application launches with the signed
certicate as an attachment.
Importing a Certicate Identity
You can import a previously generated OpenSSL certicate and private key into
Certicate Manager. The items are listed as available in the list of identities and are
available to SSL-enabled services.
The OpenSSL keys and certicates must be in PEM format.
To import an existing OpenSSL style certicate:
1 In Server Admin, select the server that has services that support SSL.
2 Click Certicates.
3 Click the Add (+) button and choose Import a Certicate Identity.
4 Drag the PEM le containing the private key to the sheet.
5 Drag the PEM le containing the public certicate to the sheet.
6 If needed, drag associated nonidentity certicates to the sheet as well.
68 Chapter 4 Enhancing Security