End Entities and Life-Cycle Management
Chapter
2
Certificate Enrollment and Life-Cycle Management
99
Access to Subsystems
Three kinds of entities can access CMS subsystems: administrators, agents, and end
entities. Administrators are responsible for the initial setup and ongoing
maintenance of the subsystems. Agents manage the day-to-day operations of each
subsystem, such as responding to requests from end entities. End entities access
Registration Manager or Certificate Manager subsystems to enroll in a PKI and to
take part in other life-cycle management operations, such as renewal or revocation.
Figure 2-8 shows the ports used by administrators, agents, and end entities. All
agent and administrator interactions with CMS subsystems occur over HTTPS.
Table 2-1
End entities, message formats, algorithms, and key pairs supported by Certificate Management
System
End entity software
Enrollment message
format over HTTP or
HTTPS
Cryptographic algorithms
No. of key pairs
Navigator 3.x
Communicator 4.0 to 4.5
KEYGEN
tag
Signing and encryption:
RSA
Signing only: RSA, DSA
Single key pair
Internet Explorer 3.x and
4.x
PKCS #10
Signing and encryption:
RSA
Signing only: RSA
Single key pair
Internet Explorer 5.x
PKCS #10
Signing and encryption:
RSA
Signing only: RSA, DSA
Single or dual key
pairs
Communicator 4.7x and
Netscape 6
CRMF and CMMF
based on new
JavaScript API
Signing and encryption:
RSA
Signing only: RSA, DSA
Single or dual key
pairs
Netscape servers
(including CMS
managers) and other
servers
PKCS #10
Signing and encryption:
RSA
Single key pair
Cisco routers (version IOS
12.04) and VPN clients
CEP
Signing and encryption:
RSA
Single key pair
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...