Certificate Authority Decisions
176
Netscape Certificate Management System Installation and Setup Guide • October 2001
The Internet Engineering Task Force (IETF), which controls many of the standards
that underlie the Internet, is currently developing public-key infrastructure X.509
(PKIX) standards. These proposed standards further refine the X.509 v3 approach
to extensions for use on the Internet. PKIX working group recommendations
should also be taken into account when planning extensions for CA certificates,
subordinate CA certificates, and end-entity certificates.
For more detailed information about extensions and recommendations for specific
types of certificates, see Appendix C, “Certificate and CRL Extensions” of CMS
Plug-ins Guide.
CA Certificate Renewal or Reissuance
When a CA signing certificate expires, all certificates signed with the CA’s
corresponding signing key become invalid. End entities use information in the CA
certificate to verify the certificate’s authenticity. If the CA certificate itself has
expired, applications cannot chain the certificate to a trusted CA.
There are two ways of dealing with CA certificate expiration:
•
Renewing a CA certificate
involves issuing a new CA certificate with the same
subject name and public and private key material as the old CA certificate, but
with an extended validity period. As long as the new CA certificate is
distributed to all users well before the old CA certificate expires, this approach
allows certificates issued under the old CA certificate to continue working for
the full duration of their validity periods. However, because of potential
conflicts between the old CA certificate and the new CA certificate, this
approach requires special care with early versions of Communicator 4.x.
•
Reissuing a CA certificate
involves issuing a new CA certificate with a new
name, public and private key material, and validity period. This approach
avoids some of the problems associated with renewing a CA certificate, but it
requires more work for both administrators and users to implement. All
certificates issued by the old CA, including those that have not yet expired,
must be renewed by the new CA.
There are advantages and disadvantages to each approach. Correct use of
extensions, for example the
authorityKeyIdentifier
extension, can also affect
the transition from an old CA certificate to a new one. You should begin planning
for CA renewal or reissuance before you install any CMS managers; consider any
ramifications your planned procedures may have for extensions, policies, and
other aspects of your initial PKI deployment.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...