Types of Certificates
3
The objects signed with object signing technology can be applets or other Java code, JavaScript
scripts, plug-ins, or any kind of file. The signature is a digital signature. Signed objects and their
signatures are typically stored in a special file called a JAR file.
Software developers and others who wish to sign files using object-signing technology must first obtain
an object-signing certificate.
1.1.2. Types of Certificates
The Certificate System is capable of generating different types of certificates for different uses and in
different formats. Planning which certificates are required and planning how to manage them, including
determining what formats are needed and how to plan for renewal, are important to manage both the
PKI and the Certificate System instances.
This list is not exhaustive; there are certificate enrollment forms for dual-use certificates for LDAP
directories, file-signing certificates, and other subsystem certificates. These forms are available
through the Certificate Manager's end-entities page, at
https://server.example.com:9444/
ca/ee/ca
. For more detailed information about the different certificates that can be created, see the
Certificate System Agent's Guide
.
When the different Certificate System subsystems are installed, the basic required certificates and
keys are generated; for example, configuring the Certificate Manager generates the CA signing
certificate for the self-signed root CA, the internal OCSP signing certificate, and the SSL server
certificate and agent user certificate. Configuring the DRM generates the storage, transport, and agent
certificates. Additional certificates can be created and installed separately.
Certificate Type
Use
Example
Client SSL certificates
Used for client authentication
to servers over SSL. Typically,
the identity of the client is
assumed to be the same as
the identity of a person, such
as an employee. Client SSL
certificates can also be used
as part of single sign-on.
A bank gives a customer an SSL client
certificate that allows the bank's servers to
identify that customer and authorize access to
the customer's accounts.
A company gives a new employee an SSL
client certificate that allows the company's
servers to identify that employee and authorize
access to the company's servers.
Server SSL certificates
Used for server authentication
to clients over SSL. Server
authentication may be used
without client authentication.
Server authentication is
required for an encrypted SSL
session. For more information,
see
Section 1.1.1.1, “SSL”
.
Internet sites that engage in electronic
commerce usually support certificate-based
server authentication to establish an encrypted
SSL session and to assure customers that
they are dealing with the web site identified
with the company. The encrypted SSL session
ensures that personal information sent over
the network, such as credit card numbers,
cannot easily be intercepted.
S/MIME certificates
Used for signed and
encrypted email. As with SSL
client certificates, the identity
of the client is assumed to
be the same as the identity
of a person, such as an
employee. A single certificate
A company deploys combined S/MIME
and SSL certificates solely to authenticate
employee identities, thus permitting signed
email and SSL client authentication but not
encrypted email. Another company issues S/
MIME certificates solely to sign and encrypt
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...