How Certificate Management System Works
44
Netscape Certificate Management System Administrator’s Guide • February 2003
Certificate Creation
The Certificate Manger issues certificates when it receives signed requests from
either its own agents (user’s who are assigned privileges to approve enrollment,
renewal, and revocation requests), from a trusted Registration Manger, or from a
third-party application that sends a signed request that is set up for CMC enroll
with the Certificate Manager.
The Certificate Manager creates the certificate using the information in the request
and from the policies or certificate profile that are set up that match this kind of
request.
Publishing of Certificates
Certificates can be published to a file, an LDAP directory, or OCSP responder. You
set up the publishing feature and set up rules that determine which certificates are
published using which method, and where exactly they are published. The
publishing system is flexible allowing you many options in configuring it. If
publishing is set up, a certificate is published to the correct location(s) whenever a
certificate is issued. See Chapter 15, “Publishing” for complete details.
Key Archival
If you install a Data Recovery Manager, the private key is requested as part of
enrollment and stored in the Data Recover Manager. See Chapter 6, “Data
Recovery Manager” for complete details.
Storing Certificate Requests and Certificates
When it issues a certificate, the Certificate Manager stores both the certificate and
the certificate request in it internal database.
Renewing Certificates
A Certificate Manager allows end-entities to renew certificates if the policies are set
up to allow for renewal. If so, the end-entity submits a renewal request in the
end-entity interface, and provides their old certificate. The Certificate Manger will
then issue a new certificate according to the policies set.
Revoking Certificates
An end-entity can submit a certificate revocation request in the end-entity
interface. They might do this if they lose their private key, or if their certificate has
been otherwise compromised. When an end-entity requests a revocation, the
request is sent to the agent services interface for agent approval.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...