Overview of Key Features
Chapter
1
Introduction to Certificate Management System
37
CA scalability via cloning
If you don’t want to create a CA hierarchy comprising root and subordinate CAs,
you can create multiple clones of a Certificate Manager and configure each clone to
issue certificates that fall within a distinct range of serial numbers. Because clone
CAs use the same CA signing key and certificate (as that of the master CA) to sign
the certificates they issue, the issuer name in all the certificates in your PKI setup
would be the same (as if they’ve been issued by a single CA).
For details on cloning a Certificate Manager, see “Cloning a Certificate Manager”
on page 286.
PKCS #11 hardware support for smart cards and crypto accelerators
Certificate Management System supports smart cards and crypto accelerators
provided by various third-party vendors of PKCS #11 version 2.01-compliant
products.
You can configure the server to use different PKCS #11 modules to generate and
store key pairs (and certificates) for the Certificate Manager, Registration Manager,
and Data Recovery Manager. Using hardware for key storage (especially for
Certificate Manager and Data Recovery Manager key pairs) reduces the risk of key
compromise, because hardware tokens don’t reveal keys or provide means for
them to be revealed, once the keys are generated in the hardware. Note that
PKCS#11 hardware devices also provide key backup and recovery features for
backup and recovery of the key material stored on the hardware token. Be sure to
refer to the PKCS #11 vendor documentation on this subject.
For information on configuring Certificate Management System to use hardware
tokens for generating and storing its key pairs and certificates, see “Tokens for
Storing CMS Keys and Certificates” on page 450.
Support for Netscape client and server products; client independence
for non-Netscape products
Certificates issued by Certificate Management System work with existing Netscape
client and server products that support SSL. The certificates also work (out of the
box) with a variety of non-Netscape, standards-compliant applications.
Highly scalable certificate data store
Certificate Management System uses a highly scalable, high-performance
certificate storage facility—a preconfigured version of Netscape Directory Server
4.x that’s automatically installed with Certificate Management System—enabling
you to issue and manage a large number of certificates. For more information, see
Chapter 12, “Setting Up Internal Database.”
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...