How Certificate Management System Works
42
Netscape Certificate Management System Administrator’s Guide • February 2003
Revocation and CRLs
CMS provides the framework for revoking certificates which can either be initiated
by an agent or by the end user themselves. An administrator can also revoke the
certificates of any of the subsystems or agents.
CMS also support CMC Revocation. When the
CMCAuth
plug-in is enabled, CMC
enrollment and CMC revocation are both enabled. CMC Revocation allows you to
send signed revocation requests that are automatically processed.
CMS is capable of producing Certificate Revocation Lists (CRLs) that it can publish
either to files, an LDAP directory, or to an OCSP responder.
You can also set up CRLs by Certificate Issuing Points allowing you to create more
than one CRL defined by the issuing point. For example, you can issue a CRL for
just CA Signing certificates, or separate CRLs for California and Florida end user
certificates.
Delta CRLs can also be produced allowing you to create CRLs that contain only the
revoked certificates since the last CRL was produced.
See Chapter 14, “Revocation and CRLs” for complete details.
How the Certificate Manager Works
This sections details the processes that a Certificate Manager goes through, and the
various configuration settings involved in those processes.
Accepting Enrollment Requests
The Certificate Manger contains an end-entity interface with various forms
associated with various types of certificates and various types of users. This
interface is customizable allowing you to only show the forms that are pertinent to
your users, change the look and feel of the pages, or add and delete fields for your
particular needs. Certificate requests that come through the Certificate Managers
end-entity interface are processed by the Certificate Manager. If it is an
agent-approved enrollment, an agent of the Certificate Manger must approve the
request. If it is an automated enrollment, the request is considered approved if the
end-entity supplies the correct information, and authenticates against the
authentication method set up. See the Netscape Certificate Management System
Customization Guide for information about customizing the end-entity interface.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...