
About Authorization
Chapter
8
Authorization
329
•
Data Recovery Manager Agents group is the agent group for a Data Recovery
Manager. No members are added to this group during installation, you must
add members after installation.
•
Online Certificate Status Manager Agents group is the agent group for an
Online Certificate Status Manager. No members are added to this group
during installation, you must add members after installation.
Trusted Managers
One subsystem can allow another subsystem to communicate via its agent port and
perform certain functions for that subsystem by forming a trust between the two.
The subsystem that is trusted is called a trusted manager.
The trusted manger relationship is set up in the following way:
•
The subsystem that trusts sets up the other subsystem as a trusted manager by
creating a user ID for the subsystem, adding it to the trusted manager group,
and storing its SSL client authentication certificate.
•
The trusted manager sets up a connector to subsystem it trusts, allowing it to
communicate with the subsystem. It does this by specifying the agent services
port information for that subsystem.
Possible Trusted Relationships
The Registration Manager and Certificate Manager can function as a trusted
manager; the Data Recovery Manager and Online Certificate Status Manager
cannot function as a trusted manager. The following trusted relationships can be
created:
•
A Registration Manager or a Certificate Manager as a trusted manager to a
Certificate Manager. This would usually be a Registration Manager, but a
Certificate Manager could be a trusted manger to another Certificate Manager
in a cloned-CA setup. See “Cloning a CA,” on page 129 for more information.
You can configure a Certificate Manager to delegate its end-entity interactions
to a trusted Registration Manager or Certificate Manager, for reasons of
localizability (proximity to end entities), customizability, security reasons, and
CA scalability; the Certificate Manager trusts the Registration Manager and
processes all certificate requests sent by this Registration Manager.
•
Registration Manager or a Certificate Manager as a trusted manager to a Data
Recovery Manager.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...