z/OS Cryptographic Services PKI Services Guide and Reference
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Steps to create IdenTrust specific certificate templates

z/OS Cryptographic Services PKI Services Guide and Reference
SA23-2286-00

Before you begin

Procedure

For each IdenTrust certificate profile you need, perform the following steps to create an IdenTrust specific certificate template in the PKI Services certificate templates file (pkiserv.tmpl):
  1. Determine if you need to define a certificate profile for a browser certificate or a server certificate.

    ________________________________________________________________

  2. Copy the appropriate sample browser or server certificate template to the PKI Services certificate templates file.

    ________________________________________________________________

  3. Change the name of the template as desired.

    ________________________________________________________________

  4. Change the nickname of the template as desired.

    ________________________________________________________________

  5. Change the <CONTENT> section to add or remove name fields and matching JavaScript as required for the desired IdenTrust profile. For example, if the subject's alternate name e-mail address is not required, remove it or make it optional.

    ________________________________________________________________

  6. Change the <CONSTANT> section as follows:
    1. Change the AuthInfoAcc values to provide the URLs required by your OCSP responder.
    2. Change the CertPolicies value to provide the policy numbers needed for the desired IdenTrust profile. (See Step 3.)

    ________________________________________________________________

When you are done: You have created an IdenTrust specific certificate template for each IdenTrust certificate profile you need. Stop and restart PKI Services to activate all of your changes.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014