iSelfSchooling.com - Copyright © 1999-2009  References  |  Job Openings  | Login (Staff | Members)
    Home  | Search more...  | Community of Sharing Knowledge (with FREE Online Video Training)
    Oracle Syntax  | Suggestions  | Private Tutoring  | Member Collaboration  | Get Translations...

  Copyright & User Agreement

    Email2aFriend  | Homepage us! |  Bookmark

Services

 Vision/Mission

 Services

 Biography

 Contact Us

 

 FREE Training

 SQL

 PL/SQL

 Forms 

 Reports

 Other TOOLS

 Fundamentals

 Performance

 OEM

 Application Server

 Grid Control

 Articles

 Prepare for OCP

 

More to know...

Acknowledgement___

 Who is who

 University Directory

 Links...

 

 

 

 

FREE Online Oracle Training for beginners and advanced - The most comprehensive Oracle tutorial

The authors do not guarantee or take any responsibility for the accuracy, or completeness of the information.

BASICS

SQL | PL/SQL

DEVELOPERS

FORMS 2 | REPORTS | Other TOOLS

DBAs

FUNDAMENTALS 2 | PERFORMANCE | OEM

ADVANCE

APPLICATION SERVER | GRID CONTROL | ARTICLES 2 3 4

Advanced - Application Server

Lesson 01 | Lesson 02 | Lesson 03 | Lesson 04 | Lesson 05 | Lesson 06 | Lesson 07 | Lesson 08 | Lesson 09 | Lesson 10 | Lesson 11 | Lesson 12 | Lesson 13 | Lesson 14 | Lesson 15 | Lesson 16 | Lesson 17 | Lesson 18 | Lesson 19 | Lesson 20 | Lesson 21 | Lesson 22 | Lesson 23 | Lesson 24 | Lesson 25 | Lesson 26 | Lesson 27 | Lesson 28 | Lesson 29 | Lesson 30 | Lesson 31 | Lesson 32 | Lesson 33 | Lesson 34 | Lesson 35 |

Lesson 23

"Most folks are as happy as they make up their minds to be."

-Abraham Lincoln (1809-1865)

How to manage Oracle Certificate Authority Policies

(LESSON 23)

 

In this hands-on, you will learn how to modify the default policy to accept the renewal of an expired certificate until 15 days of expiration.

 

In your browser, go to OCA administration page by using the following URL:

https://<hostname.domain>:4400/oca/admin

 

Click on the “Configuration Management” tab:

 

Click on the “Policy” tab:

 

In the “Policy Rules” page, select Renewals from the drop-down menu “View Policies for.”

 

Now, you should see the “Policy” page for Renewal.  You may see the default renewal policy if the values were not changed.

 

Check the “RenewalRequestConstraint” box and click Edit to edit the properties of this policy. If you have been prompted for certificate, select your OCA administrator certificate.

 

In the “Edit Policy Result: RenewalRequestConstraint” page, edit the values of your policy for the following parameters:

-         Days before expiration date

-         Days after expiration date

-         Duration of renewal (days)

 

Click in the drop-down menu under any fields, and change the values. Then click on the OK button. You may be prompted to select the OCA administrator certificate.

 

Once the OCA displays a confirmation message, you have successfully changed your certificate authority policy.

 

In order your changes get enforce, you should stop and start your OCA server.

 

You may want to set the OCA server to accept only SSL certificate if the key size is above 1024.

 

In your browser, go to OCA administration page by using the following URL:

https://<hostname.domain>:4400/oca/admin

 

Click on the “Configuration Management” tab:

 

Click on the “Policy” tab:

 

In the “Policy Rules” page, select Request from the drop-down menu “View Policies for.”

 

Now, you should see the “Policy Rules” page. Select “RSAKeyConstrints” under Policy name and click the “Edit” icon. You may be prompted to select OCA administrator certificate. Go to the “Predicate Details” section, and the click “Add Another Row” to add another predicate value. Enter value (Usage==”ssl”) into the “Predicate Expression” field. Enter value for the Maximum key size default (bits) and Minimum Key size default (bits) fields.

 

On the “Predicate Details” section, click on the “Reorder” icon to move the Usage==”ssl” predicate above Type==”client” and then click on the “OK” icon.

 

In order your changes get enforce, you should stop and start your OCA server.

 

 
 
Google
 
Web web site