📄 openca-installation.htm
字号:
ALIGN="LEFT"VALIGN="TOP">nobody.nobody</TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Use found OpenSSL command</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>Y</B></TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Continue installation</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>yes</B></TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Edit openssl.cnf</TD><TDALIGN="LEFT"VALIGN="TOP">Check <AHREF="openssl-cnf-configuration.htm">the section called <I><TTCLASS="FILENAME">openssl.cnf</TT> configuration for OpenCA</I></A></TD></TR></TBODY></TABLE></DIV> </P><P> Subsequently, to install the WWW pages that accompany the CAServer do <PCLASS="LITERALLAYOUT"> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>make install-ca-web</B></TT><br> </P> Use the following parameters when installing the WWW pages of the OpenCA component for the CAServer. <DIVCLASS="TABLE"><P><B>Table D-3. RAServer WWW Server installation parameters</B></P><TABLEBORDER="1"CLASS="CALSTABLE"><THEAD><TR><THALIGN="LEFT"VALIGN="TOP">Parameter</TH><THALIGN="LEFT"VALIGN="TOP">Value</TH></TR></THEAD><TBODY><TR><TDALIGN="LEFT"VALIGN="TOP">HTML pages directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/htdocs/ca </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">CGI directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/cgi-bin </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Continue installation</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>yes</B></TT></TD></TR></TBODY></TABLE></DIV> </P><P> Finally, follow the instructions from the WWW pages to initialise the CAServer by creating the CA private key and certificate. </P></DIV><DIVCLASS="SECT3"><H3CLASS="SECT3"><ANAME="INSTALLATION-RA">RAServer Installation</A></H3><P> This is the installation of the Registration Authority. Please refer to <AHREF="impl-openca.htm#OPENCA-LAYOUT">Figure 7-1</A> for more information. </P><DIVCLASS="NOTE"><P></P><TABLECLASS="NOTE"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="stylesheet-images/note.gif"HSPACE="5"ALT="Note"></TD><TDALIGN="LEFT"VALIGN="TOP"><P> The RAServer is supposed to be installed on a separate system than the CAServer. Furthermore, it is assumed that the steps that led to the installation of the CAServer will have to be duplicated to create the RAServer. However, for limited testing purposes, all of them could be installed on the same system. </P></TD></TR></TABLE></DIV><P> It is assumed that you have uncompressed and <ICLASS="EMPHASIS"> untarred</I> the OpenCA software with the following commands. <PCLASS="LITERALLAYOUT"> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>tar xvfz OpenCA-0.2.0.tar.gz </B></TT></P> </P><P> To install the RAServer software, enter the directory created (<TTCLASS="FILENAME">OpenCA-0.2.0</TT>) and type <PCLASS="LITERALLAYOUT"> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>make install-raserver</B></TT><br> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>make install-raserver-web</B></TT><br> </P> </P><P> You can use the following parameters when installing the OpenCA component for the RAServer. <DIVCLASS="TABLE"><P><B>Table D-4. RAServer installation parameters</B></P><TABLEBORDER="1"CLASS="CALSTABLE"><THEAD><TR><THALIGN="LEFT"VALIGN="TOP">Parameter</TH><THALIGN="LEFT"VALIGN="TOP">Value</TH></TR></THEAD><TBODY><TR><TDALIGN="LEFT"VALIGN="TOP">OpenSSL installation directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/ssl </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Base directory for RAServer</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/RAServer </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Webserver user</TD><TDALIGN="LEFT"VALIGN="TOP">nobody.nobody</TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Use found OpenSSL command</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>Y</B></TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Continue installation</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>yes</B></TT></TD></TR></TBODY></TABLE></DIV> <DIVCLASS="TABLE"><P><B>Table D-5. RAServer WWW Server installation parameters</B></P><TABLEBORDER="1"CLASS="CALSTABLE"><THEAD><TR><THALIGN="LEFT"VALIGN="TOP">Parameter</TH><THALIGN="LEFT"VALIGN="TOP">Value</TH></TR></THEAD><TBODY><TR><TDALIGN="LEFT"VALIGN="TOP">HTML pages directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/htdocs/ra </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">CGI directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/cgi-bin </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Continue installation</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>yes</B></TT></TD></TR></TBODY></TABLE></DIV> </P></DIV><DIVCLASS="SECT3"><H3CLASS="SECT3"><ANAME="INSTALLATION-RAO">RAOperator Installation</A></H3><P> This is the installation of the RA Operator. Please refer to <AHREF="impl-openca.htm#OPENCA-LAYOUT">Figure 7-1</A> for more information. </P><P> It is assumed that you have uncompressed and <ICLASS="EMPHASIS"> untarred</I> the OpenCA software with the following commands. <PCLASS="LITERALLAYOUT"> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>tar xvfz OpenCA-0.2.0.tar.gz </B></TT></P> </P><P> To install the software, enter the directory created (<TTCLASS="FILENAME">OpenCA-0.2.0</TT>) and type <PCLASS="LITERALLAYOUT"> <TTCLASS="PROMPT">root# </TT><TTCLASS="USERINPUT"><B>make install-secure</B></TT><br> </P> </P><DIVCLASS="NOTE"><P></P><TABLECLASS="NOTE"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="stylesheet-images/note.gif"HSPACE="5"ALT="Note"></TD><TDALIGN="LEFT"VALIGN="TOP"><P> Again, the RAOperator is supposed to be installed on a separate system other than the CAServer and the RAServer. Furthermore, it is assumed that the steps that led to the installation of the CAServer and the RAServer will have to be duplicated to create the RAOperator. However, for limited testing purposes, both of them could be installed on the same system. We must say that installing the CAServer, the RAServer and the RAOperators on the same system, will make it rather difficult to use and probably error-prone in the testing. </P></TD></TR></TABLE></DIV><P> <DIVCLASS="TABLE"><P><B>Table D-6. RAOperator WWW Server installation parameters</B></P><TABLEBORDER="1"CLASS="CALSTABLE"><THEAD><TR><THALIGN="LEFT"VALIGN="TOP">Parameter</TH><THALIGN="LEFT"VALIGN="TOP">Value</TH></TR></THEAD><TBODY><TR><TDALIGN="LEFT"VALIGN="TOP">HTML pages directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/htdocs/rao </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">CGI directory</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="FILENAME">/usr/local/apache/cgi-bin </TT></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP">Continue installation</TD><TDALIGN="LEFT"VALIGN="TOP"><TTCLASS="USERINPUT"><B>yes</B></TT></TD></TR></TBODY></TABLE></DIV> </P></DIV></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="INSTALL-WWW-SERVER">WWW Server installation</A></H2><P> Installation of the WWW server and the SSL/TLS WWW Server component. This will be a rather lengthly procedure, unless you use <SPANCLASS="ACRONYM">RPM</SPAN> files. This software can be found at <AHREF="impl-openca.htm#SOFTWARE-TYPE">the section called <I>Software packages</I> in Chapter 7</A>. Support information is at <AHREF="support.htm">Chapter 8</A>. </P></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="INSTALL-LDAP">LDAP installation</A></H2><P> An independent step is the installation of the LDAP software. This is usually installed on RAOperator. Recommended LDAP software is at <AHREF="impl-openca.htm#SOFTWARE-TYPE">the section called <I>Software packages</I> in Chapter 7</A>. For support information, please see <AHREF="support.htm">Chapter 8</A>. </P></DIV></DIV></DIV><DIVCLASS="NAVFOOTER"><HRALIGN="LEFT"WIDTH="100%"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top"><AHREF="how-elgamal-works.htm">Prev</A></TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"><AHREF="ospki-book.htm">Home</A></TD><TDWIDTH="33%"ALIGN="right"VALIGN="top"><AHREF="openssl-cnf-configuration.htm">Next</A></TD></TR><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top">How does El Gamal work?</TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"> </TD><TDWIDTH="33%"ALIGN="right"VALIGN="top"><TTCLASS="FILENAME">openssl.cnf</TT> configuration for OpenCA</TD></TR></TABLE></DIV></BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -