Authentication Decisions
Chapter
4
Planning Your Deployment
183
The Online Certificate Status Manager also requires at least one SSL server
certificate. For more information about the key pairs and certificates used by a
Online Certificate Status Manager, see “Online Certificate Status Manager’s Key
Pairs and Certificates” on page 449.
Authentication Decisions
CMS managers use authentication modules to verify the identity of a user
requesting a service, such as certificate enrollment. For example, a user can be
prompted to provide a name and password, and the authentication module can
check a directory entry to confirm that they are correct.
Authentication is one of the essential functions of Certificate Management System.
The main purpose of a certificate is to provide a trustworthy association between
the public key of the subject and the subject’s name and other attributes. Therefore
the manner in which administrators, agents, and end entities are authenticated,
especially for operations related to certificate enrollment, requires careful planning
and control throughout the lifetime of a PKI deployment.
For examples of some different approaches to authentication during certificate
enrollment, see Chapter 2, “Certificate Enrollment and Life-Cycle Management.”
For a detailed overview of authentication management using Certificate
Management System, see Chapter 15, “Setting Up End-User Authentication.”
Policy Decisions
CMS managers use policies to evaluate or verify incoming certificate enrollment or
management requests from end entities and to determine the outcome. For
example, in the case of certificate enrollment request, the outcome is the issued
certificate.
Decisions regarding policies depend on both the subsystem involved and your
overall topology. Whether your CA signing certificate is self-signed or not, it
represents part of a certificate hierarchy. For example, a CA may be a root CA for
subordinate CAs that issue certificates to different parts of a large organization, or
it may be one of the subordinate CAs that chain up to an internal root CA, or it may
be a linked CA that chains up to a third party.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...