![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 838](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697838.webp)
The SSL Handshake
838
Netscape Certificate Manager System Administrator’s Guide • June 2003
•
In the case of client authentication, the client encrypts some random data with
the client’s private key—that is, it creates a digital signature. The public key in
the client’s certificate can correctly validate the digital signature only if the
corresponding private key was used. Otherwise, the server cannot validate the
digital signature and the session is terminated.
The sections that follow provide more details on server authentication and client
authentication.
Server Authentication
Netscape’s SSL-enabled client software always requires server authentication, or
cryptographic validation by a client of the server’s identity. As explained in Step 2
of “The SSL Handshake,” which begins on page 836, the server sends the client a
certificate to authenticate itself. The client uses the certificate in Step 3 to
authenticate the identity the certificate claims to represent.
To authenticate the binding between a public key and the server identified by the
certificate that contains the public key, an SSL-enabled client must receive a “yes”
answer to the four questions shown in Figure K-2. Although the fourth question is
not technically part of the SSL protocol, it is the client’s responsibility to support
this requirement, which provides some assurance of the server’s identity and thus
helps protect against a form of security attack known as “man in the middle.”
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...