One case in which the trust attributes of a certificate needs to be modified is if client authentication is used with the Gateway. An example of client authentication is PDC (Personal Digital Certificate). The CA that issues the PDCs must be trusted by the Gateway, and the CA certificate must be marked "T" for SSL.
If the Gateway is set up to communicate with an HTTPS site, the CA of the HTTPS site server certificate must be trusted by the Gateway, and the CA certificate must be marked "C" for SSL.
 To Modify the Trust Attributes for a Certificate
To Modify the Trust Attributes for a CertificateAs root, run the certadmin script.
| gateway-install-root/SUNWportal/bin/certadmin -n gateway-profile-name | 
where gateway-profile-name is the name of the Gateway instance.
The certificate administration menu is displayed.
| 1) Generate Self-Signed Certificate 2) Generate Certificate Signing Request (CSR) 3) Add Root CA Certificate 4) Install Certificate From Certificate Authority (CA) 5) Delete Certificate 6) Modify Trust Attributes of Certificate (e.g., for PDC) 7) List Root CA Certificates 8) List All Certificates 9) Print Certificate Content 10)Quit choice: [10] 6 | 
Choose option 6 on the certificate administration menu.
Enter the name of the certificate. For example, Thawte Personal Freemail CA.
| Please enter the name of the certificate? Thawte Personal Freemail CA | 
Enter the trust attribute for the certificate.
| Please enter the trust attribute you want the certificate to have [CT,CT,CT] | 
The certificate trust attribute will be changed.