Previous Topic: Generate the Certificate Authority Key Pair

Next Topic: Test the New Certificate

Generate the DSA Certificates

You must now create the individual DSA personality certificates. Each of these certificates will be signed by the root CA certificate authority.

Each of the DSA certificates will be stored in slot 2, along with the CA certificate.

For this example, use the table below when entering the responses:

DSA Name

Certificate Distinguished Name Attributes

Democorp-Master-democorp

cn=DXServer,o=Democorp,c=AU

UNSPSC-Master-unspsc

cn=DXServer,o=UNSPSC,c=AU

Router-Master

cn=DXServer,c=AU

To generate the DSA certificates

  1. Enter the following command:
    ctcert c -crootCA -k -ldsa-name -s2
    
  2. Enter the user PIN for the slot.
  3. Enter the following information about the certificate:

    Leave any other fields blank.

  4. Repeat for each of the DSAs that are required.