Certificates and Authentication
776
Managing Servers with Netscape Console • December 2001
evaluation process can employ a variety of standard authorization
mechanisms, potentially using additional information in an LDAP directory,
company databases, and so on. If the result of the evaluation is positive, the
server allows the client to access the requested resource.
As you can see by comparing Figure J-5 to Figure J-4, certificates replace the
authentication portion of the interaction between the client and the server. Instead
of requiring a user to send passwords across the network throughout the day,
single sign-on requires the user to enter the private-key database password just
once, without sending it across the network. For the rest of the session, the client
presents the user’s certificate to authenticate the user to each new server it
encounters. Existing authorization mechanisms based on the authenticated user
identity are not affected.
How Certificates Are Used
•
Types of Certificates
•
SSL Protocol
•
Signed and Encrypted Email
•
Form Signing
•
Single Sign-On
•
Object Signing
Types of Certificates
Five kinds of certificates are commonly used with Netscape products:
•
Client SSL certificates.
Used to identify clients to servers via SSL (client
authentication). Typically, the identity of the client is assumed to be the same
as the identity of a human being, such as an employee in an enterprise. See
“Certificate-Based Authentication,” which begins on page 774, for a
description of the way client SSL certificates are used for client authentication.
Client SSL certificates can also be used for form signing and as part of a single
sign-on solution.
Examples:
A bank gives a customer a client SSL certificate that allows the
bank’s servers to identify that customer and authorize access to the customer’s
accounts. A company might give a new employee a client SSL certificate that
allows the company’s servers to identify that employee and authorize access to
the company’s servers.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...