iii
About This Guide xvii
1. Recommended Knowledge ........................................................................................... xvii
2. What Is in This Guide .................................................................................................. xvii
3. Examples and Formatting .............................................................................................. xix
3.1. File Locations for Examples and Commands ....................................................... xix
3.2. Using Mozilla LDAP Tools .................................................................................. xix
3.3. Default Port Numbers ......................................................................................... xix
3.4. Guide Formatting ............................................................................................... xix
4. Additional Reading ........................................................................................................ xx
5. Giving Feedback ........................................................................................................... xxi
6. Document History ......................................................................................................... xxi
1. Overview 1
1.1. Features ...................................................................................................................... 1
1.1.1. Subsystems ...................................................................................................... 1
1.1.2. Interfaces .......................................................................................................... 2
1.1.3. Logging ............................................................................................................. 2
1.1.4. Auditing ............................................................................................................. 2
1.1.5. Self-Tests .......................................................................................................... 3
1.1.6. Authorization ..................................................................................................... 3
1.1.7. Security-Enhanced Linux Support ....................................................................... 3
1.1.8. Authentication .................................................................................................... 3
1.1.9. Registration Authority ......................................................................................... 4
1.1.10. SCEP .............................................................................................................. 4
1.1.11. Certificate Issuance .......................................................................................... 4
1.1.12. Certificate Profiles ............................................................................................ 5
1.1.13. CRLs .............................................................................................................. 5
1.1.14. Publishing ....................................................................................................... 5
1.1.15. Notifications ..................................................................................................... 5
1.1.16. Jobs ................................................................................................................ 5
1.1.17. Dual Key Pairs ................................................................................................ 6
1.1.18. HSMs and Crypto Accelerators ......................................................................... 6
1.1.19. Support for Open Standards ............................................................................. 6
1.2. How the Certificate System Works ................................................................................ 7
1.2.1. About the Certificate Manager ............................................................................ 7
1.2.2. How the Certificate Manager Works .................................................................... 9
1.2.3. Data Recovery Manager .................................................................................. 11
1.2.4. Online Certificate Status Manager .................................................................... 11
1.2.5. Token Key Service ........................................................................................... 12
1.2.6. Token Processing System ................................................................................ 12
1.3. Deployment Scenarios ................................................................................................ 12
1.3.1. Single Certificate Manager ............................................................................... 12
1.3.2. Certificate Manager and DRM .......................................................................... 13
1.3.3. Cloned Certificate Manager .............................................................................. 14
1.3.4. Smart Card Enrollment .................................................................................... 15
1.4. System Architecture ................................................................................................... 15
1.4.1. Certificate System Instance .............................................................................. 17
1.4.2. HTTP Engine .................................................................................................. 17
1.4.3. User Interfaces ................................................................................................ 17
1.4.4. JSS and the JNI Layer .................................................................................... 18
1.4.5. NSS ................................................................................................................ 18
1.4.6. PKCS #11 ....................................................................................................... 19
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...