How Fortezza Crypto Cards are Certified
230
Managing Servers with Netscape Console • December 2001
Each enterprise user must request and obtain a Fortezza crypto card from a CA.
Typically, a user who wants to access a Fortezza-secured server plugs the Fortezza
crypto card into the PCMCIA reader. By inserting the card and typing in a personal
identification number (PIN), the user tells the client to do the following:
•
Load all of the CA certificates on the card into memory
•
Trust the CA certificates provided on the card
•
If requested, use the keys on the card for client authentication
How Fortezza Crypto Cards are Certified
The US government established the policy approval authority (PAA), a regulating
body, to ensure that only valid users are given authenticated Fortezza cards.
The policy approval authority delegates its authority to policy creation authorities
(PCAs). These are groups that may represent a branch of the government or a large
corporation. Policy creation authorities in turn delegate authority to certificate
authorities (CAs).
Certificate authorities are the individuals who actually verify users’ key
information. CAs program, activate, and issue cards to government employees and
to individuals who conduct business with the government. A single CA might
handle the encryption needs of a small company, a single department in a large
company, or a department in a government agency.
Fortezza Keys, Certificates, and Encryption
CAs program Fortezza crypto cards with any combination of key and certificate
management approaches and encryption algorithms. Some of these approaches
and algorithms are described briefly here. For more information about how keys,
certificates, and encryption work in general, see Appendix B, “Introduction to
Public-Key Cryptography” and Appendix C, “Introduction to SSL.”
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...