
Support for Open Standards
Chapter 1
Overview
63
•
Tutorials—“How To” tutorial to help demonstrate how you can create your own
plug-in modules for CS. Each tutorial includes sample Java source code, environment
and build script and a detailed “cookbook” describing how to build and install these
plug-in modules. Additionally, some tutorials may also contain sample configuration
files.
Support for Open Standards
This section summarizes the standard message formats and protocols supported by CS.
Certificate Management Formats and Protocols
CS supports the following certificate management formats and protocols. For more details
about the proposed PKIX standards listed here, see
http://www.ietf.org/html.charters/pkix-charter.html
(under Internet
Drafts).
•
Simple Certificate Enrollment Protocol (SCEP)
. A certificate management protocol
jointly developed by Cisco Systems and VeriSign, Inc. CEP is an early implementation
of CMC (described later in this list). CEP specifies how a device communicates with a
CA, including how to retrieve the CA’s public key, how to enroll a device with the CA,
and how to retrieve a CRL. CEP uses PKCS #7 and PKCS #10.
•
Certificate Request Message Format (CRMF).
A message format used to convey a
request for a certificate to a Registration Manager or Certificate Manager. A standard
from the Internet Engineering Task Force (IETF) PKIX working group.
•
Certificate Management Message Formats (CMMF).
Message formats used to
convey certificate requests and revocation requests from end entities to a Registration
Manager or Certificate Manager and to send a variety of information to end entities. A
proposed standard from the IETF PKIX working group. CMMF is subsumed by
another proposed standard, CMC (next item).
•
Certificate Management Messages over CS (CMC).
A general interface to
public-key certification products based on CS and PKCS #10, including a certificate
enrollment protocol for DSA-signed certificates with Diffie-Hellman public keys. A
standard from the IETF PKIX working group. CMC incorporates CRMF and CMMF.
•
Cryptographic Message Syntax (CS).
A superset of PKCS #7 syntax used for digital
signatures and encryption. A proposed standard from the IETF PKIX working group.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...