How Certificate Management System Works
Chapter
1
Overview
41
•
End-Entity Services Interface—The end-entity interface is a customizable
HTML interface that can be used for end-entities to enroll in your PKI, renew
certificates, revoke their own certificates, and pick up issued certificates. It
contains forms for different types of enrollments, and for the enrollment
different types of end-entities. The Certificate Manager and the Registration
Manager have an end-entity services interface, the Data Recovery Manager
and OSCP Manager do not.
Logs
Each subsystem produces extensive system and error logs that record various
events and system errors so that you can monitor and debug the system. All log
records are stored in your local file system for quick and easy retrieval.
CMS allows you to sign log files digitally before archiving them or distributing
them for audit purposes. This feature enables you to check whether the log files
were tampered with after being signed.
The log feature is configurable, allowing you to select logging levels as well as
what is logged. You can also create custom logs so that events can be separated by
the categories you choose. See “Logs,” on page 261 for complete details.
Auditing
CMS maintains audit trails for all events—certificate requests and issuance,
revocation requests, CRL publication, and so on. These audit records enable you to
detect any unauthorized access or activity.
CMS allows you to set up special users called Auditors who have exclusive access
to these logs, allowing independent auditing of your PKI.
You can customize audit logs to include the information you want to include in the
audit log. See “Signed Audit Log,” on page 275 for complete details.
Internal Database
Each subsystem has its own internal database where it stores such things as issued
certificates, certificate requests, and so on. The internal database is an instance of
Netscape Directory Server that is used exclusively as the internal database for this
subsystem. See “The Internal Database,” on page 288 for complete details.
Authorization
CMS is preconfigured with four types of users who have various access to the
system:
•
Administrators who can perform any administrative or configuration task.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...