About Authorization
Chapter
8
Authorization
329
•
Data Recovery Manager Agents group is the agent group for a Data Recovery
Manager. No members are added to this group during installation, you must
add members after installation.
•
Online Certificate Status Manager Agents group is the agent group for an
Online Certificate Status Manager. No members are added to this group
during installation, you must add members after installation.
Trusted Managers
One subsystem can allow another subsystem to communicate via its agent port and
perform certain functions for that subsystem by forming a trust between the two.
The subsystem that is trusted is called a trusted manager.
The trusted manger relationship is set up in the following way:
•
The subsystem that trusts sets up the other subsystem as a trusted manager by
creating a user ID for the subsystem, adding it to the trusted manager group,
and storing its SSL client authentication certificate.
•
The trusted manager sets up a connector to subsystem it trusts, allowing it to
communicate with the subsystem. It does this by specifying the agent services
port information for that subsystem.
Possible Trusted Relationships
The Registration Manager and Certificate Manager can function as a trusted
manager; the Data Recovery Manager and Online Certificate Status Manager
cannot function as a trusted manager. The following trusted relationships can be
created:
•
A Registration Manager or a Certificate Manager as a trusted manager to a
Certificate Manager. This would usually be a Registration Manager, but a
Certificate Manager could be a trusted manger to another Certificate Manager
in a cloned-CA setup. See “Cloning a CA,” on page 129 for more information.
You can configure a Certificate Manager to delegate its end-entity interactions
to a trusted Registration Manager or Certificate Manager, for reasons of
localizability (proximity to end entities), customizability, security reasons, and
CA scalability; the Certificate Manager trusts the Registration Manager and
processes all certificate requests sent by this Registration Manager.
•
Registration Manager or a Certificate Manager as a trusted manager to a Data
Recovery Manager.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...