Features
30
Netscape Certificate Management System Administrator’s Guide • February 2003
•
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and
creating and publishing CRLs. See Chapter 3, “Certificate Manager” for
complete details.
•
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate
Manager in which its signed requests are processed. See Chapter 4,
“Registration Manager” for complete details.
•
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, “OCSP Responder” for
complete details.
•
The Data Recovery Manager is an optional subsystem that provides private
encryption key storage and retrieval. See Chapter 6, “Data Recovery Manager”
for complete details.
Certificate Manager Flexibility and Scalability
The Certificate Manager can be deployed in several ways to provide flexibility in
your PKI including support for multiple registration authorities tied to a single CA,
the ability to act as a root or subordinate CA and cloning of a CA to allow CAs with
identical functionality using the same keys and certificates but using different sets
of serial numbers for their issued certificates.
Single CA Supports Multiple Registration Authorities
CMS lets you separate the registration process from the certificate-signing process
with the help of Registration Managers. You can run multiple Registration
Managers remotely, all reporting to a single Certificate Manager, to verify user
identities and process certificate issuance, renewal, and revocation requests. The
remote Registration Managers forward their completed and approved requests to
the Certificate Manager for it to sign and issue the certificate automatically.
The Certificate Manager’s ability to support multiple Registration Managers makes
it more scalable and also adds an extra layer of security for the CA. For example,
you can set a policy that requires all clients to go through a remote Registration
Manager, and then have the remote Registration Manager route all client requests
to the Certificate Manager located inside a firewall.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...