384
a.
PKI architecture
Entity
An entity is an end user of PKI products or services, such as a person, an organization, a device like a router
or a switch, or a process running on a computer.
CA
A certificate authority (CA) is a trusted authority responsible for issuing and managing digital certificates. A
CA issues certificates, specifies the validity periods of certificates, and revokes certificates as needed by
publishing CRLs.
RA
A registration authority (RA) is an extended part of a CA or an independent authority. An RA can implement
functions including identity authentication, CRL management, key pair generation and key pair backup. It
only examines the qualifications of users; it does not sign certificates. Sometimes, a CA assumes the
registration management responsibility and no independent RA exists. The PKI standard recommends that
an independent RA be used for registration management to achieve higher security of application systems.
PKI repository
A PKI repository can be a Lightweight Directory Access Protocol (LDAP) server or a common database. It
stores and manages information like certificate requests, certificates, keys, CRLs and logs, and it provides
a simple query function.
LDAP is a protocol for accessing and managing PKI information. An LDAP server stores user information and
digital certificates from the RA server and provides directory navigation service. From an LDAP server, an
entity can retrieve digital certificates of its own and other entities.
Applications of PKI
The PKI technology can satisfy the security requirements of online transactions. As an infrastructure, PKI has
a wide range of applications. Here are some application examples.
VPN
A virtual private network (VPN) is a private data communication network built on the public communication
infrastructure. A VPN can leverage network layer security protocols (for instance, IPSec) in conjunction with
PKI-based encryption and digital signature technologies to achieve confidentiality.
Содержание V1910
Страница 1: ...1 HP V1910 Switch Series User Guide 5998 2238 Part number 5998 2238 Document version 2 ...
Страница 85: ...73 c Display the rate settings of ports ...
Страница 102: ...90 a Port traffic statistics ...
Страница 186: ...174 a The MAC tab Click Add in the bottom to enter the page as shown in b b Create a MAC address entry ...
Страница 252: ...240 b The Port Setup tab ...
Страница 260: ...248 d The Port Setup tab ...
Страница 362: ...350 a Ping operation summary ...
Страница 421: ...409 c Configure authorized IP ...
Страница 479: ...467 Index A B C D E F G H I L M O P Q R S T V W ...