You can update key/certificate pairs and standalone certificates in the following ways:
The new certificate must be valid before CA SiteMinder® Federation Standalone can use it to update an expiring certificate. Certificates are updated and become available immediately after they are imported. If the new certificate is not valid, as determined by its validity interval, CA SiteMinder® Federation Standalone cannot use the new certificate.
To import only a trusted certificate, use a certificate file that has a PEM or DER encoding. The standard extension for files of these types is *.crt or *.cer. If the file ends in .p12 or .pfx, it is processed as a certificate data store file containing key/certificate pairs. Finally, if a file ends in .p7 or .p7b, it is processed as a signed response file. Anything else is treated as a certificate file, and CA SiteMinder® Federation Standalone tries to load a certificate from it.
Note: If you update certificates for a federated environment, you do not have to update any federation objects using the expiring certificates.
|
Copyright © 2013 CA.
All rights reserved.
|
|