Certificates and Authentication
Appendix
B
Introduction to Public-Key Cryptography
255
CA Hierarchies
In large organizations, it may be appropriate to delegate the responsibility for
issuing certificates to several different certificate authorities. For example, the
number of certificates required may be too large for a single CA to maintain;
different organizational units may have different policy requirements; or it may be
important for a CA to be physically located in the same geographic area as the
people to whom it is issuing certificates.
It’s possible to delegate certificate-issuing responsibilities to subordinate CAs. The
X.509 standard includes a model for setting up a hierarchy of CAs like that shown
in Figure B-6.
Figure B-6
Example of a Hierarchy of Certificate Authorities
In this model, the root CA is at the top of the hierarchy. The root CA’s certificate is
a
self-signed certificate:
that is, the certificate is digitally signed by the same
entity—the root CA—that the certificate identifies. The CAs that are directly
subordinate to the root CA have CA certificates signed by the root CA. CAs under
the subordinate CAs in the hierarchy have their CA certificates signed by the
higher-level subordinate CAs.
Organizations have a great deal of flexibility in terms of the way they set up their
CA hierarchies. Figure B-6 shows just one example; many other arrangements are
possible.
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...