814
Netscape Certificate Management System Administrator’s Guide • February 2003
Certificate Enrollment Protocol (CEP)
A certificate management protocol jointly
developed by Cisco Systems and VeriSign, Inc. CEP is an early implementation of
Certificate Management Messages over Cryptographic Message Syntax (CMC).
CEP specifies how a device communicates with a CA, including how to retrieve the
CA’s public key, how to enroll a device with the CA, and how to retrieve a CRL.
CEP uses PKCS #7 and PKCS #10. For more information about CEP, see
http://www.cisco.com/warp/public/778/security/821_pp.htm
.
certificate extensions
An X.509 v3 certificate contains an extensions field that
permits any number of additional fields to be added to the certificate. Certificate
extensions provide a way of adding information such as alternative subject names
and usage restrictions to certificates. A number of standard extensions have been
defined by the PKIX working group. Older versions of Netscape browsers and
servers support Netscape-specific extensions that were required (mainly to
indicate certificate usage) before standard extensions were defined.
certificate fingerprint
A one-way hash associated with a certificate. The number
is not part of the certificate itself, but is produced by applying a hash function to
the contents of the certificate. If the contents of the certificate changes, even by a
single character, the same function produces a different number. Certificate
fingerprints can therefore be used to verify that certificates have not been tampered
with.
Certificate Management Messages over Cryptographic Message Syntax (CMC)
Message format used to convey a request for a certificate to a Registration Manager
or Certificate Manager. A proposed standard from the Internet Engineering Task
Force (IETF) PKIX working group. For detailed information, see
http://www.ietf.org/internet-drafts/draft-ietf-pkix-cmc-02.txt
.
Certificate Management Message Formats (CMMF)
Message formats used to
convey certificate requests and revocation requests from end entities to a
Registration Manager or Certificate Manager and to send a variety of information
to end entities. A proposed standard from the Internet Engineering Task Force
(IETF) PKIX working group. CMMF is subsumed by another proposed standard,
Certificate Management Messages over Cryptographic Message Syntax (CMC). For
detailed information, see
http://www.ietf.org/internet-drafts/draft-ietf-pkix-cmmf-02.txt
.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...