These release notes contain important information about Version
4.2, Service Pack 2 (SP2) release of iPlanet Certificate Management System
(CMS). New features and enhancements, installation notes, known problems,
and other late-breaking issues are addressed here. Read this document before
you begin installing and using Certificate Management System.
These release notes contain the following sections:
Platform/OS | CMS 4.2-SP2 | CMS 4.2 |
Compaq Tru64TM |
|
|
HP UXTM |
|
|
IBM AIXTM |
|
|
Microsoft Windows NTTM |
|
|
Sun SolarisTM |
|
|
Other Components | CMS 4.2-SP2 | CMS 4.2 |
Netscape Administration Server |
|
|
Netscape Directory Server |
|
|
Netscape Console |
|
|
Netscape Personal Security Manager (PSM) |
|
Check this directory: <server_root>/psm12 |
Network Security Services (NSS) |
|
|
OCSP Responder |
|
|
CMS SDK and Samples | Are installed with the rest of the server binaries:
|
Are installed with the rest of the server binaries:
|
Command-line Tools | All tools are installed at: <server_root>/bin/cert/tools | Are installed at <server_root>/bin/cert/tools
and <server_root>/cms_sdk/samples/exttools |
CMS Documentation | Better organized, more books; see CMS Documentation. | List of documentation is available after installation at: <server_root>/manual/index.html |
Feature | CMS 4.2-SP2 | CMS 4.2 |
Authentication methods for end users |
|
|
Forms for certificate enrollment |
|
|
Forms for certificate renewal |
|
|
Forms for certificate revocation |
|
|
Policies for governing the formulation of certificates |
|
Constraints-specific policies (for governing the formulation
of certificate content, such as the key size, signing algorithm, validity
period, and so on):
|
Policies for adding certificate extensions |
|
Extension-specific policies (for adding extensions
to certificates):
|
Schedulable jobs |
|
|
Event-driven notifications |
|
|
Publishing of certificates and CRLs |
|
|
Logging |
|
|
Backup and recovery |
|
|
Certificate Manager |
|
|
Registration Manager |
|
|
Key Recovery Manager |
|
|
Agent Services interface |
|
|
For the latest information about Certificate Management System, including
current release notes, technical notes, and deployment information, check
this web site: http://docs.iplanet.com/docs/manuals/cms.html
In addition to the requirements listed below, make sure you have ample swap space or virtual memory allocated for the system on which you intend to install Certificate Management System.
AIX Platform Requirements OS Version AIX 4.3.3 (with relevant Java 2 patches) Machine PowerPC_604 or faster RAM 1 GB Hard disk storage space requirements Total required is approximately 400 MB, as follows:
- Total transient space required during installation: 100 MB
- Hard disk storage space required for installation:
- Space required for setup, configuration, and running the server: approximately 250 MB
- Additional space to allow for database growth in pilot deployment: approximately 50 MB
- Total disk storage space for installation: approximately 300 MB
Compaq Tru64 Platform Requirements OS Version Compaq Tru64 v4.0D (with relevant Java 2 patches) Machine 267MHz alpha or faster RAM 256 MB Hard disk storage space requirements Total required is approximately 400 MB, as follows:
- Total transient space required during installation: 100 MB
- Hard disk storage space required for installation:
- Space required for setup, configuration, and running the server: approximately 250 MB
- Additional space to allow for database growth in pilot deployment: approximately 50 MB
- Total disk storage space for installation: approximately 300 MB
HP-UX Platform Requirements OS Version HP-UX B.11.00 (with relevant Java 2 patches) Machine 240MHz PA_RISC 9000/800 or faster RAM 512 MB Hard disk storage space requirements Total required is approximately 420 MB, as follows:
- Total transient space required during installation: 120 MB
- Hard disk storage space required for installation:
- Space required for setup, configuration, and running the server: approximately 250 MB
- Additional space to allow for database growth in pilot deployment: approximately 50 MB
- Total disk storage space for installation: approximately 300 MB
Solaris Platform Requirements OS Version Solaris 2.6, 2.7, or 8 (with relevant Java 2 patches) Machine Ultra 1 or faster RAM 128 MB (required) Hard disk storage space requirements Total required is approximately 400 MB, as follows:
- Total transient space required during installation: 100 MB
- Hard disk storage space required for installation:
- Space required for setup, configuration, and running the server: approximately 250 MB
- Additional space to allow for database growth in pilot deployment: approximately 50 MB
- Total disk storage space for installation: approximately 300 MB
Windows NT Platform Requirements OS Version Windows NT 4.0 with Service Pack 5 or 6 Machine Pentium 350 or faster File system NTFS or FAT RAM 128 MB of RAM (recommended) Hard disk storage space requirements Total required is approximately 350 MB, as follows:
- Total transient space required during installation: 100 MB
- Hard disk storage space required for installation:
- Space required for setup, configuration, and running the server: approximately 200 MB
- Additional space to allow for database growth in pilot deployment: approximately 50 MB
- Total disk storage space for installation: approximately 250 MB
Other Requirements
- On Unix systems, you must install as root in order to use well-known port numbers (such as 443) that are less than 1024. If you do not plan to use port numbers less than 1024, you do not need to install as root. If you plan to run as root, you should also install as root and specify nobody as the default run-as user and group.
- On a Windows NT system, you must install as Administrator or a user with Administrator privileges (that is, the user must be in the Administrators group).
If you remove the password from the adm.conf file, every time you start Netscape Console, you'll be prompted for the Administration Server administrator's password.
Once you've provided the password, if the server you're trying to connect to uses SSL, you'll be asked for the SSL token password you specified when you installed the server certificate.
To remove the clear text Administration Server password:
To configure the server to run a CGI script:
The "<space>Corporation" gets left off; that is, the words trailing the space get truncated in the UI. [# 395046]
In addition, in the summary notification sent for unpublished certificates, the words "VALUE UNKNOWN" will show up before the table-title row. All it means is that there are no expired certificates. [# 400973]
Note that despite the error message, the instance will be created properly and you will be able to configure it. [# 395304]
"Public storage key: used to encrypt an end entity's private encryption key for long-term storage.
"Private storage key: used to decrypt an end entity's stored private encryption key after m of n recovery agents have authorized the recovery operation."
In fact, the opposite is true. The documentation should read:
"Public storage key: used to decrypt an end entity's stored private encryption key after m of n recovery agents have authorized the recovery operation.used to encrypt an end entity's private encryption key for long-term storage.
"Private storage key: used to encrypt an end entity's private encryption key for long-term storage."This section of the documentation will be fixed in the next version of the product.
"Siroe, Inc."in the text field for the O component. [# 391583]
If you need further assistance or information about Certificate Management System or if you need to report problems with this product, contact technical support. You may also contact us through our newsgroup for support, questions, answers, and the latest information:
snews://secnews.netscape.com/netscape.dev.certificateYou might also find it useful to subscribe to the following newsgroups, where security-related topics are discussed:
snews://secnews.netscape.com/netscape.dev.sslSo that we can best assist you in resolving problems, please be sure to include the following information:
snews://secnews.netscape.com/netscape.dev.security
When | Where | What's been changed/added |
11/01/2002 | Job Scheduling/Notification | Registration Manager cannot configure automatic renewal notifications. [# 464982] |
11/01/2002 | Definitions of public and private storage keys. [# 4727931] |
Use of iPlanet Certificate Management System
is subject to the terms described in the license agreement accompanying it.
Copyright © 2002 Sun Microsystems, Inc. Some preexisting portions
Copyright © 2001 Netscape Communications Corp. All rights reserved.
Sun, Sun Microsystems, the Sun logo, Java, iPlanet, and all
Sun, Java, and iPlanet based trademarks and logos are trademarks or registered
trademarks of Sun Microsystems, Inc. in the United States and other countries.
Netscape and the Netscape N logo are registered trademarks of Netscape Communications
Corporation in the U.S. and other countries. Other Netscape logos, product
names, and service names are also trademarks of Netscape Communications Corporation,
which may be registered in other countries.