Federal Bridge CA
Chapter
3
Certificate Manager
127
When an end entity makes the request, they are asked to present their certificate. If
they have the certificate and the key materials, the request is processed and sent to
the Certificate Manager and the certificate is revoked. Once approved, the signed
request is sent to the Certificate Manager and the certificate is revoked. The
Certificate Manager marks the certificate as revoked in its database, and adds it to
any CRLs that are applicable.
An agent can revoke any certificate issued by the Certificate Manager. They do this
by searching for the certificate in the agent services interface and then marking it
revoked.
Once a certificate is revoked, it is marked revoked in the database, and in the
publishing directory if the Certificate is set up for publishing.
If you enabled and configured the internal OCSP service, the service determines
the status of certificates by looking them up in the internal database and reporting
on the status of the certificate.
You can set up an automated notifications that send an email message to the end
entity when their certificate is revoked. You set this up by enabling and
configuring the Certificate Revoked notification message, and customizing the
email template associated with this notification.
Federal Bridge CA
CMS supports Federal Bridge Certificate Authority (FBCA) by providing the
capability to issue, import, and publish cross-pair CA certificates.
With cross-pair certificates, one CA signs and issues a cross-pair certificate to a
second CA, and the second CA signs and issues a cross-pair certificate to the first
CA. Both CAs then store and or publish both certificates as a
crossCertificatePair
.
This may be done when you want to honor certificates issued by a CA that does not
chain up to your root CA. By establishing a trust between your CA and another CA
through a cross-pair CA certificate, you can download this cross-pair certificate
using it to trust the certificates that are issued by the other CA.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...