Changes between Version 39 and Version 40 of InstallDiscoveryBrowse


Ignore:
Timestamp:
05/06/08 15:04:08 (11 years ago)
Author:
pjkersha
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • InstallDiscoveryBrowse

    v39 v40  
    229229{{{ 
    230230cd /etc/ndg/ows_server/conf/certs 
    231 openssl genrsa -des3 -out browse-pdp.key 2048 
    232 chmod 400 browse-pdp.key 
     231openssl genrsa -des3 -out browse.key 2048 
     232chmod 400 browse.key 
    233233}}} 
    234234 
     
    238238 
    239239{{{ 
    240 openssl req -new -key browse-pdp.key -out browse-pdp.csr 
    241 }}} 
    242  
    243 You will be prompted for the fields that will make up the Distinguished Name of the certificate when it is issued.  It is recommended that a Common Name is set to `BrowsePDP`.   Organisation can be `NDG` and Organisation Unit, the name of your organisation.  Other fields can be left blank.   
     240openssl req -new -key browse.key -out browse.csr 
     241}}} 
     242 
     243You will be prompted for the fields that will make up the Distinguished Name of the certificate when it is issued.  It is recommended that a Common Name is set to `Browse`.   Organisation can be `NDG` and Organisation Unit, the name of your organisation.  Other fields can be left blank.   
    244244 
    245245[mailto:P.J.Kershaw@rl.ac.uk E-mail] the request file so that it can signed and sent back to you: 
    246246 
    247247{{{ 
    248 mail p.j.kershaw@rl.ac.uk -s 'Certificate Request' < browse-pdp.csr 
    249 }}} 
    250  
    251 When you receive the signed certificate copy it into `/etc/ndg/ows_server/conf/certs/browse-pdp.crt`. Once you have the certificate, the certificate request file `browse-pdp.csr` can be removed.  You should also install a copy of your CA certificate and the CA certificates of all the other NDG sites that you trust.  If you don't know how to get this contact [mailto:P.J.Kershaw@rl.ac.uk Phil] for help.  Copy the CA certificates into `/etc/ndg/ows_server/conf/certs/` 
     248mail p.j.kershaw@rl.ac.uk -s 'Certificate Request' < browse.csr 
     249}}} 
     250 
     251When you receive the signed certificate copy it into `/etc/ndg/ows_server/conf/certs/browse.crt`. Once you have the certificate, the certificate request file `browse.csr` can be removed.  You should also install a copy of your CA certificate and the CA certificates of all the other NDG sites that you trust.  If you don't know how to get this contact [mailto:P.J.Kershaw@rl.ac.uk Phil] for help.  Copy the CA certificates into `/etc/ndg/ows_server/conf/certs/` 
    252252 
    253253Certificate files can be checked with `openssl` e.g. the following command will print out the Distinguished Name for the CA certificate: 
     
    259259The new certificate and private key and CA certificate files should be referenced in the discovery config `/etc/ndg/ows_server/conf/ndgDiscovery.config`) as follows: 
    260260{{{ 
    261 signingCertFilePath=certs/browse-pdp.crt 
     261signingCertFilePath=certs/browse.crt 
    262262}}} 
    263263