xxxviii
Engineering Task Force (IETF) to be the successor to SSL version 3.0. TLS is a
configurable option provided in Oracle Net Manager.
■
Support for Hardware Security Modules, including Oracle Wallet Manager
Integration
In this release, Oracle Advanced Security supports hardware security modules
which use APIs that conform to the RSA Security, Inc., Public-Key
Cryptography Standards (PKCS) #11. In addition, it is now possible to create
Oracle Wallets that can store credentials on a hardware security module for
servers, or private keys on tokens for clients. This provides roaming
authentication to the database.
Hardware security modules can be used for the following functions:
–
Store cryptographic information, such as private keys, which provides
stronger security
–
Perform cryptographic operations to off load RSA operations from the
server, freeing the CPU to respond to other transactions
■
CRL (Certificate Revocation Lists) and CRLDP (CRL Distribution Point)
Support for Certificate Validation
In the current release, you now have the option to configure certificate
revocation status checking for both the client and the server. Certificate
revocation status is checked against
CRL
s
which are located in file system
directories, Oracle Internet Directory, or downloaded from the location
specified in the
CRL Distribution Point
(CRL DP) extension on the certificate.
The
orapki
utility has also been added for CRL management and for
managing Oracle wallets and certificates.
See Also:
Chapter 7, "Configuring Secure Sockets Layer
Authentication"
for configuration details
See Also:
■
"Configuring Your System to Use Hardware Security Modules"
on page 7-48 for configuration details
■
"Creating a Wallet to Store Hardware Security Module
Credentials"
on page 8-11
Summary of Contents for Database Advanced Security 10g Release 1
Page 17: ...xvii ...
Page 20: ...xx ...
Page 24: ...xxiv ...
Page 42: ...xlii ...
Page 44: ......
Page 102: ......
Page 124: ......
Page 246: ...Managing Certificates 8 28 Oracle Database Advanced Security Administrator s Guide ...
Page 284: ......
Page 384: ......
Page 414: ...Physical Security D 6 Oracle Database Advanced Security Administrator s Guide ...
Page 518: ...Index 10 ...