Hardware Cryptographic Accelerators
320
Netscape Certificate Management System Administrator’s Guide • February 2003
Hardware Cryptographic Accelerators
Certificate Management System allows you to use hardware cryptographic
accelerators with external tokens. Many of the accelerators provide the following
security features:
•
Fast SSL connections—speed is important if you want your Certificate
Manager, Registration Manager, or Data Recovery Manager to be able to
accommodate a high number of simultaneous enrollment or service requests.
•
Hardware protection of private keys—these devices behave like smart cards, in
that they do not allow the private keys to be copied or removed from the
hardware token. This is important if you are concerned about the risks
associated with key theft from an active attacker of your online Registration
Manager or Certificate Manager.
Configuring the Server’s Security Preferences
Configuring a CMS manager’s security preferences involves identifying the
following:
•
The SSL server certificates a server must use for authenticating to the end
entity, agent, and administration interfaces. For details, see “Configuring the
Server to Use Separate SSL Server Certificates” on page 321.
•
The SSL client certificate a Certificate Manager must use for authenticating to
the publishing directory (if the Certificate Manager is configured to publish
certificates and CRLs to the directory). For details, see “Getting an SSL Client
Certificate for a Subsystem” on page 322.
•
The version of SSL that an instance of CMS must use during SSL
communication. The latest version is SSL version 3, but many older clients use
SSL version 2. Because client authentication is required for performing
privileged operations, you must enable SSL version 3 ciphers supported by
CMS. For details, see “Configuring the Server’s Security Preferences,” on page
320.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...