7.4.1.3. Case III: HSM to Security Databases Migration

7.4.1.3. Case III: HSM to Security Databases Migration

  1. Extract the public/private key pairs from the HSM. The format for the extracted key pairs should be portable, such as a PKCS #12 file.

    The pk12util tool provided by the Certificate System cannot extract public/private key pairs from an HSM because of requirements in the FIPS 140-1 standard which protect the private key portion of an entry. To extract this information, contact the HSM vendor for more information. The extracted keys should not have any dependencies, such as nickname prefixes, on the HSM.

  2. Copy the extracted public/private key pairs from the old server to the new server.

    cp old_server_root/alias/ServerCert.p12 
    /var/lib/instance_ID/alias/ServerCert.p12
    
    cp old_server_root/alias/caSigningCert.p12 
    /var/lib/instance_ID/alias/caSigningCert.p12
    
    cp old_server_root/alias/ocspSigningCert.p12 
    /var/lib/instance_ID/alias/ocspSigningCert.p12
    

  3. Log into the new server as the Certificate System user, and open the Certificate System alias/ directory.

    cd /var/lib/instance_ID/alias/
    

  4. Log in as root, and set the file user and group to the Certificate System user and group.

    su
    
    chown user:group ServerCert.p12
    
    chown user:group caSigningCert.p12
    
    chown user:group ocspSigningCert.p12

  5. Log out as root. As the Certificate System user, set the file permissions on the PKCS #12 files.

    chmod 00600 ServerCert.p12
    
    chmod 00600 caSigningCert.p12
    
    chmod 00600 ocspSigningCert.p12
    

  6. Import the public/private key pairs of each entry from the PKCS #12 files into the new security databases.

    pk12util -i ServerCert.p12 -d . 
    
    Enter Password or Pin for "NSS Certificate DB":********
    Enter password for PKCS12 file: ********
    pk12util: PKCS12 IMPORT SUCCESSFUL
    
    pk12util -i caSigningCert.p12 -d . 
    
    Enter Password or Pin for "NSS Certificate DB":********
    Enter password for PKCS12 file: ********
    pk12util: PKCS12 IMPORT SUCCESSFUL
    
    pk12util -i ocspSigningCert.p12 -d . 
    
    Enter Password or Pin for "NSS Certificate DB":********
    Enter password for PKCS12 file: ********
    pk12util: PKCS12 IMPORT SUCCESSFUL
    

  7. Optionally, delete the PKCS #12 files.

    rm ServerCert.p12
    
    rm caSigningCert.p12
    
    rm ocspSigningCert.p12
    

  8. Set the trust bits on the public/private key pairs that were imported into the new security databases.

    certutil -M -n "Server-Cert cert-old_CA_instance" 
    -t "cu,cu,cu" -d . 
    
    certutil -M -n "caSigningCert cert-old_CA_instance" 
    -t "CTu,CTu,CTu" -d .
    
    certutil -M -n "ocspSigningCert cert-old_CA_instance" 
    -t "CTu,Cu,Cu" -d . 
    

  9. Open the CS.cfg configuration file.

    cd /var/lib/instance_ID/conf/
    
    vi CS.cfg
    

  10. Edit the ca.signing.cacertnickname and ca.ocsp_signing.cacert.nickname attributes to reflect the new CA information.

    ca.signing.cacertnickname=
     caSigningCert cert-old_CA_instance
    ca.ocsp_signing.cacertnickname=
     ocspSigningCert cert-old_CA_instance
  11. If there is CA-DRM connectivity, then also modify the ca.connector.KRA.nickname attribute.

    ca.connector.KRA.nickname=caSigningCert cert-old_CA_instance

  12. In the same directory, edit the serverCertNick.conf file to contain the old certificate nickname. For example:

    vi serverCertNick.conf
    
    Server-Cert cert-old_CA_instance