Cloning a CA
Chapter
3
Certificate Manager
129
CMS also provides a publishing mapper for CA certificates that can be used for
publishing cross-pair certificates,
LDAPCA
, designating which LDAP entry should
be used to store the
crossCertificatePair
. A publisher,
LDAPCrossPairPublisher
, is also set up specifying the attribute used to store the
cross-pair certificate in the CA entry. This is set to
crossCertificatePair;binary
.
See Chapter 15, “Publishing” for more information about publishing.
Cloning a CA
Cloning a Certificate Manager is the process of creating two server processes
performing the same CA functions: you create another instance of a Certificate
Manager and configure it to use the same CA signing key and certificate and issue
certificates with serial numbers that do not conflict or overlap with the serial
numbers of the Certificate Manager that’s being cloned or with the serial numbers
of any other clones. The Certificate Manager that’s being cloned is called the master
Certificate Manager or master CA.
You can use the cloning feature for CA scalability and for setting up a PKI with
CAs organized in a flat structure as opposed to a hierarchical structure. For
example, if you don’t want your PKI to be a CA hierarchy comprising root and
subordinate CAs, you can create multiple clones of a Certificate Manager and
configure each clone to issue certificates that fall within a distinct range of serial
numbers. Because clone CAs use the same CA signing key and certificate (as that of
the master CA) to sign the certificates they issue, the issuer name in all the
certificates in your PKI setup would be the same, as if they’ve been issued by a
single CA.
The other advantage of cloning is that when you setup a clone Certificate Manager,
it automatically sends the revocation status of the certificates it has issued to the
master Certificate Manager. The clone Certificate Manager uses the master
Certificate Manager’s agent port to communicate this information; the
communication is SSL-client authenticated. This way, the master Certificate
Manager has the complete list of certificates revoked by all clone Certificate
Managers and is able to generate a consolidated list of revoked certificates or a
complete CRL.
Because the master Certificate Manager has the complete CRL, if you enable the
OCSP-service feature built into the Certificate Manager, it can function as a
full-fledged OCSP responder for your PKI—that is, irrespective of which clone
Certificate Manager has issued the certificate, OCSP-compliant clients can directly
query the master Certificate Manager for the revocation status of a certificate.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...