Topology Decisions
166
Netscape Certificate Management System Installation and Setup Guide • October 2001
The arrangement shown in Figure 4-1 is equivalent to the capabilities provided by
Netscape Certificate Server 1.x—with the addition of new Certificate Management
System features such as Digital Signature Algorithm (DSA) signing, support for
PKCS #11, and support for a wider variety of end-entity protocols.
Certificate Manager and Registration Manager
Many organizations need to separate the role of the Registration Manager from the
role of the Certificate Manager. This separation can be useful, for example, if
different groups of end entities are subject to different authentication policies or
work in different geographic locations.
Each group of end entities interacts with a designated Registration Manager that
processes requests from end entities and sends them to a Certificate Manager. The
Certificate Manager can accept requests from both end entities and Registration
Managers. For example, end entities at the home office might deal directly with the
Certificate Manager, while end entities at a branch office might deal with their own
Registration Manager. Alternatively, the Certificate Manager might be configured
to accept requests only from Registration Managers, thus shielding the CA from
end entities.
As stated earlier, a single CMS instance cannot contain both a Certificate Manager
and a Registration Manager. A Certificate Manager that needs to interact with end
entities other than Registration Managers provides all Registration Manager
capabilities itself.
A Registration Manager can be installed in one CMS instance and its related
Certificate Manager in another CMS instance. The separate instances can be located
in the same server group, in different server groups on the same machine, or on
different machines.
Figure 4-2 shows a Registration Manager and its Certificate Manager in separate
instances on separate machines. All communication between the Certificate
Manager and the Registration Manager takes place over HTTPS.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...