Common Criteria Deployment Scenarios
Appendix
C
Understanding the Common Criteria Evaluated CMS Setup
691
Common Criteria Deployment Scenarios
As long as the subsystems you install are installed and configured following the
Common Criteria Environment rules and guidelines contained in this chapter, you
can deploy CMS in any deployment scenario you wish. You can set up a root CA,
for example, a CA subordinate to a CMS CA, a CA subordinate to a public
third-party CA, or have any number of CAs in vertical or horizontal chains as long
as they follow the constraints contained in the CA signing certificate. If you are
setting up the FBCA (cross-certification) feature, you need to cooperate with the
administrator of the remote CA to set up the trust between the two certificates.
You can configure one or more RAs to any CA you set up. You can also install a
Data Recovery Manager to any CA that you install. Though connecting a Data
Recovery Manager to a Registration Manager is one possible CMS deployment
scenario, it is not currently part of the Common Criteria Evaluation. You can install
and configure an OCSP responder to any CA you install and configure, or you can
have one OCSP responder work with multiple CAs.
Features That Are Not Part of the Common
Criteria Environment
The Common Criteria Environment tests all of the features and ways of
configuring CMS except for the following, which are not part of the Common
Criteria Environment:
•
Using anything other than hardware tokens to create and store CIMC keys and
certificates.
•
Using the remote startup plain-text password cache,
password.conf.
•
Using the administrative interface, CMS console, in non-SSL client
authentication mode.
•
Cloning a Certificate Manager.
•
Connecting a Data Recovery Manager to a Registration Manager.
•
Running the internal database, or any publishing LDAP database in non-SSL
client authentication mode.
•
Using the non-profile Policy feature for enrollment.
•
Using the certificate-based authentication, face-to-face authentication
(in-person authentication) available in a Registration Manager,
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...