About Authorization
326
Netscape Certificate Management System Administrator’s Guide • June 2003
Authentication of Auditors
Auditors are authenticated into the CMS console by using their login and
password. Once authenticated, they can only view the audit logs, they are not able
to edit other parts of the system.
You can change the method of authentication for an auditor to SSL client
authentication. See “Setting up Certificate Authentication for the CMS Console,”
on page 247 for complete details.
Agents
Agents are users who have been assigned end-entity certificate- and
key-management privileges. Agents can access the agent services interface, and
perform tasks associated with their subsystem in that interface. For a complete list
of agent tasks, see the CMS Agent’s Guide.
You create agents by creating a user, assigning membership in the appropriate
agent group, and identifying certificates that the agents must use for SSL client
authentication to the subsystem (for it to service requests from the agents).
Each CMS subsystem has its own agents whose role is defined by the subsystem.
Each subsystem installed in a CMS instance must have at least one agent, and there
is no limit to the number of agents a subsystem can have.
Authentication of Agents
CMS identifies and authenticates a user with agent privileges by checking the user’s
SSL client certificate in its internal database. See “Agent Certificates,” on page 335.
For information on obtaining and revoking agent certificates, see “Revocation
Status Checking of Agent Certificates,” on page 339.
Groups for Agents
Each substystem has its own agent group:
•
Certificate Manager Agents group is the agent group for a Certificate Manager.
During installation the administrator can be designated as the first agent; you
are given a choice to add the administrator to the agents group. Note that this
choice also enables or disables the ability to add users to multiple groups. If
you choose to enable this feature, users can be assigned to more than one
group. If you disable this feature, users will not be allowed to be added to more
than one group.
•
Registration Manager Agents group is the agent group for a Registration
Manager. No members are added to this group during installation, you must
add members after installation.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...