![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 43](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697043.webp)
How Certificate Management System Works
Chapter
1
Overview
43
The Certificate Manager acts as a Certificate Authority (CA). It can be configured as
a self-signing CA, where it is the root CA, or it can act as a subordinate CA, where
it obtains its own signing certificate from a public CA.
Scalability
You can configure more than one CA either forming a vertical or horizontal chain
of CAs. For example, you can create a root CA for your deployment that is either
self-signing or subordinate to a public CA and then have one or more CAs below
this root CA. Those CAs can have further CAs below them forming a chain of CA’s.
You can also clone a CA so that two CAs are set up in an identical manner and use
the same CA signing Certificate, but each uses a different set of serial numbers for
the certificates it issues.
Federal Bridge Certificate Authority
CMS also allows you to create a trusted relationship between two separate CAs by
issuing and storing cross-signed certificates between these two CAs. This feature of
the PKI is called Federal Bridge Certificate Authority (FBCA). This feature allows
you to trust certificates issued by a CA outside of your PKI that shares a
cross-signed certificate with the CA in your PKI.
Certificate Manager Functionality
The Certificate Manager issues, renews, and revokes certificates when it receives
signed requests from either its own agents (user’s who are assigned privileges to
approve enrollment, renewal, and revocation requests), from a trusted Registration
Manager, or from a third-party application that sends a signed request using its
agent certificate that is set up for CMC enroll or revoke with the Certificate
Manager.
The Certificate Manager also compiles lists of revoked certificates, called Certificate
Revocation Lists (CRLs) that it can publish to files, an LDAP directory, or an OCSP
service.
The Certificate Manager maintains a database of issued certificates, and of
processed requests, so that it can track renewal, expiration, and revocation.
Types of Certificates That are Managed
CMS can issue and manage certificates for Certificate Authority signing certificates,
cross-signed pair certificates (FBCA), SSL server certificates, router certificates,
VPN client certificates, and end user certificates.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...