Some Enrollment Scenarios
84
Netscape Certificate Management System Installation and Setup Guide • October 2001
Some Enrollment Scenarios
Successful PKI deployment requires flexible and easy enrollment for end entities as
well as ongoing support for certificate life-cycle management—that is, management of
each certificate from enrollment through encryption key storage (if necessary),
renewal, and revocation. The preceding section describes the internal flow of
control among servlets, authentication modules, and policy modules in a CMS
manager (see Figure 2-1 for a summary). The examples that follow illustrate the
flexibility that the CMS architecture supports among end entities, Registration
Managers, Certificate Managers, and existing customer databases, security
systems, and directories.
•
Firewall Considerations
•
Extranet/E-Commerce: Acme Sales Corp.
•
PIN Registration: Atlas Manufacturing
•
VPN Client Enrollment and Revocation
•
Router Enrollment and Revocation
For the sake of simplicity, these examples do not show the role of the Data
Recovery Manager. For more information about data recovery, see “Data Recovery
Manager” on page 48.
For more information about certificate life-cycle management, see “End Entities
and Life-Cycle Management” on page 98.
Firewall Considerations
Most of the examples that follow show a Certificate Manager inside the firewall
and a Registration Manager outside the firewall. Other variations are possible, but
this arrangement is often appropriate. These are some of the advantages:
•
The most sensitive elements of the deployment—the Certificate Manager,
internal databases, directories, and so on—have the additional protection of
the firewall.
•
The Certificate Manager can have additional physical protection, if
desired—such as storage in a locked room and agent authentication by means
of smart cards.
•
All communication between the Registration Manager and the Certificate
Manager takes place over SSL with mutual authentication—that is, both client
and server authentication via X.509 v3 certificates.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...