Displaying default keys and certificate authorities

This section describes how to view trusted certificate authorities and display default keys within a key database.


About this task

A trusted certificate authority (CA) issues and manages public keys for data encryption. A key database is used to share public keys that are used for secure connections. The tasks that follow show how to view the certificate authorities that are in your database, along with their expiration dates.


Procedure

  • Display the default key entry as follows:

    1. Start the IKEYMAN user interface.

    2. Click Key Database File from the main UI, then click Open.

    3. Enter your key database name in the Open dialog box, or click the key.kdb file, if using the default. Click OK.

    4. Enter your password in the Password Prompt dialog box, then click OK.

    5. Click Personal Certificates in the Key Database content frame, and click the CA certificate label name.

    6. Click View/Edit and view the certificate default key information in the Key Information window.

  • Display a list of trusted certificate authorities (CAs) in a key database as follows:

    1. Start the IKEYMAN user interface.

    2. Click Key Database File from the main UI, then click Open.

    3. Enter your key database name in the Open dialog box, or click the key.kdb file if you are using the default.

    4. Enter your correct password in the Password prompt dialog box, and click OK.

    5. Click Signer Certificates in the Key database content frame.

    6. Click Signer Certificates, Personal Certificates,or Certificate Requests, to view the list of CAs in the Key Information window.


What to do next

The version of iKeyman that is provided by the bundled Java™ Runtime Environment (JRE) does not add a default list of signer certificates to newly-created key databases. Add default signer certificates in iKeyman, as follows:

  1. Select Signer Certificates from the drop-down menu in the iKeyman window.

  2. Click Populate.

  3. Click the grey boxes next to the certificate authority names (Entrust, RSA Data Security, Thawte, Verisign) so they display as checked.

  4. Click OK.


Related