The Certificate System subsystems have been tested using the following tokens:
Gemalto T OP IM FIPS CY2 64K token, both as a smart card and GemPCKey USB form factor key
Gemalto Cyberflex e-gate 32K token (Red Hat Enterprise Linux and Mac systems)
Safenet 330J Java smart card
Smart card testing was conducted using the SCM SCR331 CCID reader.
The only card manager applet supported with Certificate System is the CoolKey applet which ships with
Red Hat Enterprise Linux 5.3.
3.5. Supported HSM
Red Hat Certificate System supports the Safenet Chrysalis-IT LunaSA and nCipher netHSM 2000
hardware security modules (HSM) by default. The tested and supported versions are listed in Table 4,
“Tested HSM Versions for Red Hat Certificate System 8.0”. Other HSMs can be added by loading their
libraries in the local machine and configuring the default configuration files after the Certificate System
packages are installed, but before configuring the instances; this is described in the Administrator's
Guide.
Table 4 . Tested HSM Versions for Red Hat Certificate System 8.0
HSM Firmware Appliance Software Client Soft ware
Safenet Chrysalis-IT S
LunaSA
4.5.2 3.2.4 3.2.4
nCipher netHSM 2000 2.33.60 11.10
4. Installing Red Hat Certificate System Subsystems
The following sections contain information on the prerequisites and procedures for installing Certificate
System subsystems, including basic information that you need to begin installing the packages.
Installing and configuring Certificate System 8.0 subsystems is described in more detail in the
Installation Guide.
4.1. Installation Notes
Packages are non-relocatable. T he Red Hat Certificate System base packages can not be installed
to a user-designated location.
Remove any installed libsqlite RPM files before installing the RA. The sqlite RPM files that
ship with RA cause conflicts with those files.
4.2. Install the Required JDK
Certificate System requires Sun JDK 1.6.0. T his JDK must be installed separately.
The OpenJDK can be installed by using yum or by downloading the packages directly from
http://openjdk.java.net/install/. For example:
yum install java-1.6.0-openjdk
Comentarios a estos manuales