Apple 10.6 Server User Manual


 
Chapter 4 Enhancing Security 71
5 Click Save.
Renewing an Expiring Certicate
Certicates have an expiration date and must be renewed periodically. Renewing a
certicate is the same as replacing a certicate with a newly generated one with an
updated expiration date.
To renew an expiring certicate:
1 Request a new certicate from the CA.
If you are your own CA, create one using your own root certicate.
2 In Server Admin in the Server list, select the server that has the expiring certicate.
3 Click Certicates.
4 Select the Certicate Identity to renew.
5 Click the Action button and select “Replace Certicate with Signed or Renewed
Certicate.”
6 Drag the renewed certicate to the sheet.
7 Click Replace Certicate.
Replacing an Existing Certicate
If you change the DNS name of the server or any virtual hosts on the server, you must
replace an existing certicate with an updated one.
To replace an expiring certicate:
1 Request a certicate from the CA.
If you are your own CA, create one using your own root certicate.
2 In Server Admin in the Server list, select the server that has the expiring certicate.
3 Click Certicates.
4 Select the Certicate Identity to replace.
5 Click the Action button and select “Replace Certicate with Signed or Renewed
Certicate.”
6 Drag the replacement certicate to the sheet.
7 Click Replace Certicate.
Using Certicates
In Server Admin, services like Web, Mail, VPN, and so on display a pop-up list of
certicates that the administrator can choose from. The services vary in appearance
and therefore the pop-up list location varies. Consult the administration guide for the
service you’re trying to use with a certicate.