Overview of Key Features
36
Netscape Certificate Management System Installation and Setup Guide • October 2001
Single CA supports multiple registration authorities
Certificate Management System lets you separate the registration process from the
certificate-signing process with the help of Registration Managers. You can run
multiple Registration Managers remotely, all reporting to a single Certificate
Manager, to verify user identities and process certificate signing requests. The
remote Registration Managers forward their completed and approved requests to
the Certificate Manager for it to sign and issue the certificate automatically.
The Certificate Manager’s ability to support multiple Registration Managers makes
it more scalable and also adds an extra layer of security for the CA. For example,
you can set a policy that requires all clients to go through a remote Registration
Manager, and then have the remote Registration Manager route all client requests
to the Certificate Manager located inside a firewall.
For more information, see “Trusted Managers” on page 394.
Ability to function as both a root and a subordinate CA in a CA
hierarchy
Certificate Management System can function as a root or parent CA; in this case, the
server signs its own CA signing key as well as other CA signing keys, enabling you
to create your own CA hierarchy. You can also install the server to function as a
subordinate CA; in this case, the server gets its CA signing key signed by another CA
in an existing CA hierarchy.
For details on installing the Certificate Manager as a root or subordinate CA, see
Part 2, “Planning and Installation.”
Ability to function as a linked CA
Certificate Management System can function as a linked CA, chaining up to many
third-party or public CAs for validation; this provides cross-company trust, so
applications can verify certificate chains outside the company certificate hierarchy.
You chain a Certificate Manager to a third-party CA by requesting the Certificate
Manager’s CA signing certificate from the third-party CA.
For details on installing the Certificate Manager as a linked CA, see Part 2,
“Planning and Installation.”
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...