Ports
Chapter
7
Administrative Basics
287
For example, the URL to a Certificate Manager agent interface would look like this:
https://demoCA.example.com:5600/ca
If you change the agent port number, be sure to inform your agent users.
End-Entity Ports
For requests from end entities, CMS can listen to two ports, an SSL (encrypted) port
and a non-SSL port. End entities make these requests from the end entity services
interface.
CMS provides the following services through the HTTP and HTTPS ports:
•
The HTTP port can be used to service end-entity-initiated PKI requests, such as
enrollment, renewal, and revocation; enrollment requests can include requests
from Cisco routers (using the CEP protocol); general certificate retrieval
requests, such as retrieving a single certificate identified by a serial number,
listing certificates based on certain criteria (for example, an LDAP search filter
defined over standard attributes), and getting a CA’s certificate chain. You can
disable this port if it will not be used.
•
The HTTPS port can be used to service end-entity-initiated PKI requests, such
as enrollment, renewal, and revocation; enrollment requests can include
requests from Cisco routers (using the CEP protocol); general certificate
retrieval requests, such as retrieving a single certificate identified by a serial
number, listing certificates based on certain criteria (for example, an LDAP
search filter defined over standard attributes), and getting a CA’s certificate
chain. The HTTPS port uses SSL authentication providing a secure transfer of
data to this port.
Similar to the HTTP port, you can enable or disable the HTTPS port. For
example, if you don’t want end-entity interaction with a Certificate Manager,
you can disable the HTTPS port. For details, see “Changing a Port Number” on
page 288.
If this CMS instance is for a Certificate Manager and if the Certificate Manager is
configured to service OCSP requests from OCSP-compliant clients, then this port
must be enabled so that OCSP-compliant clients can successfully query the
Certificate Manager for the revocation status of a certificate. For details, see
“Setting Up a Certificate Manager with OCSP Service” on page 171.
Similarly, for issuing certificates to routers (using the CEP protocol), the port must
be enabled. For details, see “CEP Enrollment,” on page 414.”
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...