Features
32
Netscape Certificate Management System Administrator’s Guide • June 2003
•
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and
creating and publishing CRLs. See Chapter 3, “Certificate Manager” for
complete details.
•
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate
Manager in which its signed requests are processed. See Chapter 4,
“Registration Manager” for complete details.
•
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, “OCSP Responder” for
complete details.
•
The Data Recovery Manager is an optional subsystem that provides private
encryption key storage and retrieval. See Chapter 6, “Data Recovery Manager”
for complete details.
Certificate Manager Flexibility and Scalability
The Certificate Manager can be deployed in several ways to provide flexibility in
your PKI. Features include:
•
support for multiple registration authorities tied to a single CA
•
the ability to act as a root or subordinate CA
•
high-availability cloning to allow CAs with identical functionality, keys and
certificates to issue certificates with different sets of serial numbers.
Single CA Supports Multiple Registration Authorities
CMS lets you separate the registration process from the certificate-signing process
with the help of Registration Managers. You can run multiple Registration
Managers remotely, all reporting to a single Certificate Manager, to verify user
identities and process certificate issuance, renewal, and revocation requests. The
remote Registration Managers forward their completed and approved requests to
the Certificate Manager for it to sign and issue the certificate automatically.
The Certificate Manager’s ability to support multiple Registration Managers makes
it more scalable and also adds an extra layer of security for the CA. For example,
you can set a policy that requires all clients to go through a remote Registration
Manager, and then have the remote Registration Manager route all client requests
to the Certificate Manager located inside a firewall.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...