Certificate Manager Deployment Considerations
Chapter
3
Certificate Manager
89
If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, see the
following document:
http://www.itl.nist.gov/div897/pubs/fip186.htm
.
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
Many people no longer consider an RSA key of length less than 1024 bits to be
cryptographically strong. Export and other regulations permitting, it may be a
good rule of thumb to start with 1024 bits and consider increasing the length to
4096 bits for certificates that provide access to highly sensitive data or services.
However, the question of key length has no simple answers. Every organization
must make its own decision based on its own security requirements. For more
information on key length and encryption strength, see Appendix D of Managing
Servers with Netscape Console.
Certificate Manager Interfaces
When you install a Certificate Manager, three interfaces are enabled. The
installation wizard lets you choose the ports these interfaces listen on. The
following interfaces, and associated ports will be created:
•
An Administrative interface that is accessible by default only to members of
the Administrator and Auditor group. You specify the first administrator
when you install the subsystem. Administrators can configure any of the
settings of the server. Most basic functionality and subsystem specific
configuration to the subsystem can be done using the administrative interface.
The administrative interface listens to requests on the SSL Administration Port.
This is the port the CMS administrative interface listens to, and that is accessed
by administrators and auditors using the Java based CMS Console GUI
application.
•
An Agent Services interface that is accessible by default only to members of the
Agent group. You can choose to include the first administrator to also be the
first agent when you install the subsystem. Agents are users who can perform
tasks associated with the processing of requests and management of
certificates. A Certificate Manager Agent can change the status, change the
details, reject or approve certificate and revocation requests, revoke certificates,
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...