Topology Decisions
170
Netscape Certificate Management System Installation and Setup Guide • October 2001
Like a Certificate Manager, a Data Recovery Manager has special physical security
requirements, since a compromised Data Recovery Manager would have
devastating security consequences for your entire PKI. You may therefore want to
keep the Data Recovery Manager in a special locked room or building, a choice that
can affect your deployment strategy.
Certificate Manager, Data Recovery Manager,
and Registration Manager
The three CMS subsystems can be deployed in many different relationships. Figure
4-4 illustrates some of the issues involved in deploying all three subsystems by
showing the relationships among a single Certificate Manager, a single
Registration Manager, and a single Data Recovery Manager, each installed in a
different CMS instance on a different machine.
The Registration Manager handles all end-entity interactions and communicates
with the Certificate Manager and the Data Recovery Manager over HTTPS. The
Registration Manager is configured to request the end entity’s private encryption
key (in encrypted form) and send it to the Data Recovery Manager during the
enrollment process. Before the Registration Manager sends the certificate request to
the Certificate Manager for processing, the Registration Manager must receive
verification from the Data Recovery Manager that the private key has been
received and stored and that it corresponds to the end entity’s public key.
Only the Certificate Manager can be configured to enable or disable LDAP
publishing or to publish to separate directories. The Certificate Manager also has
the complete record of issued certificates, so that it can perform the publishing
tasks, as shown in the figure.
Many other combinations are possible. For example, the Data Recovery Manager
and the Certificate Manager might be in the same instance; there might be multiple
Registration Managers in different instances, all dealing with the same Data
Recovery Manager and Certificate Manager; or the Certificate Manager might also
handle some end-entity interactions. It’s also possible to set up both Certificate
Managers and Registration Managers such that each has a hierarchy of subordinate
managers.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...