![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 33](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697033.webp)
Features
Chapter
1
Overview
33
Root or Subordinate CA
CMS can function as a root CA; in this case, the server signs its own CA signing
certificate as well as other CA signing certificates, enabling you to create your own
CA hierarchy. You can also install the server to function as a subordinate CA; in this
case, the server gets its CA signing key signed by another CA in an existing CA
hierarchy. See “Self-Signed Root vs. Subordinate CA,” on page 86 for complete
details.
Linked CA
CMS can function as a linked CA, chaining up to many third-party or public CAs for
validation; this provides cross-company trust, so applications can verify certificate
chains outside the company certificate hierarchy. You chain a Certificate Manager
to a third-party CA by requesting the Certificate Manager’s CA signing certificate
from the third-party CA.
CA Cloning
If you don’t want to create a CA hierarchy comprising root and subordinate CAs,
you can create clones of a Certificate Manager and configure each clone to issue
certificates that fall within a distinct range of serial numbers. Because cloned CAs
and master CAs use the same CA signing key and certificate to sign the certificates
they issue, the issuer name in all the certificates will be the same. Cloned CAs and
the master Certificate Managers they are based on issue certificates as if they are a
single CA, and can be placed on different hosts for high availability failover
support. See “Cloning a CA,” on page 131 for details. Also see Appendix ,
“Configuring CMS for High Availability” for information on configuring clones for
failover in a CMS system.
Interfaces
Each of the subsystems contains interfaces allowing interaction with various
portions of the subsystem. All four subsystems share a common administrative
interface. All four subsystems have an agent interface specific to that subsystem
allowing agents to perform the tasks assigned to them. A Certificate Manager and a
Registration Manager have an end-entity services interface allowing end-entities to
enroll in the PKI.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...