Prerequisites
25
issue and the nature of the certificate chain. This may not be acceptable for some PKI deployments.
One benefit of chaining to a public CA is that the third party is responsible for submitting the root CA
certificate to a web browser or other client software, which is a major advantage for certificates that
are accessed by different companies with browsers that cannot be controlled by the administrator.
•
Subordination to a Certificate System CA
. Setting up a Certificate System CA as the root CA means
that the Certificate System administrator has control over all subordinate CAs by setting policies that
control the contents of the CA signing certificates issued. A subordinate CA issues certificates by
evaluating its own authentication and certificate profile configuration, without regard for the root CA's
configuration.
It is easiest to make the first CA installed a self-signed root, so that it is not necessary to apply to a
third party and wait for the certificate to be issued. Before deploying the full PKI, however, consider
whether to have a root CA, how many to have, and where both root and subordinate CAs will be
located.
2.2. Prerequisites
This section covers required information such as the supported platforms, the packages installed, and
dependencies and programs.
•
Section 2.2.1, “Supported Platforms”
•
Section 2.2.2, “Required Programs and Dependencies”
•
Section 2.2.3, “Packages Installed”
2.2.1. Supported Platforms
Certificate System server packages are available for the following platforms:
• Red Hat Enterprise Linux AS 4 (Intel 32-bit)
• Red Hat Enterprise Linux AS 4 (Intel 64-bit)
• Red Hat Enterprise Linux ES 4 (Intel 32-bit)
• Red Hat Enterprise Linux ES 4 (Intel 64-bit)
• Solaris 9 (Sparc 64-bit)
Certificate System Enterprise Security Client packages are available for the following platforms:
• Apple Macintosh OS X 10.4.x (Tiger) (Power PC 32-bit, Intel Mac)
• Microsoft Windows XP Professional (Intel 32-bit)
• Red Hat Enterprise Linux AS 4 (Intel 32-bit)
• Red Hat Enterprise Linux AS 4 (Intel 64-bit)
• Red Hat Enterprise Linux ES 4 (Intel 32-bit)
• Red Hat Enterprise Linux ES 4 (Intel 64-bit)
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...