IT Environment Assumptions
Appendix
B
Common Criteria Environment: Setup and Operations
679
Password and Certificate Storage
Plan for the storage of any passwords and certificates. Also plan your user
password policy. Make sure everyone knows and adheres to these policies.
Hardware Token
This environment requires a FIPS 140-1 level 3 certified hardware cryptographic
module.
You need to install the software and hardware for this hardware token before
installing and configuring the subsystems. You will also setup the hardware token
for use with CMS after installing CMS, but before installing a subsystem. Use the
hardware token to create subsystem certificates during installation of each
subsystem.
Protection of Private and Secret Keys
CMS certificate private keys and secret keys are to be generated and stored in a
FIPS 140-1 level 3 certified hardware cryptographic token.
The CMS private (asymmetric) keys are:
•
Private key associated with the CA signing certificate.
•
Private key associated with the RA-to-CA SSL client certificate.
•
Private key associated with the OCSP Responder signing certificate.
•
Private key associated with the CA-to-DRM SSL client certificate.
•
Private key associated with the DRM transport certificate.
•
Private key associated with the CA, RA, DRM, and OCSP SSL server
certificates.
•
Private key associated with the audit log signing certificate.
•
Private key associated with the DRM storage certificate used for encrypting
user subject encryption private keys (for DRM key archival).
The CMS secret (symmetric) key is:
•
Symmetric key used to encrypt passwords for password cache (single-sign-on).
See “Password Cache,” on page 253.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...