IT Environment Assumptions
Appendix
B
Common Criteria Environment: Setup and Operations
713
Password and Certificate Storage
Plan for the storage of any passwords and certificates. Also plan your user
password policy. Make sure everyone knows and adheres to these policies.
Hardware Token
This environment requires a FIPS 140-1 level 3 certified hardware cryptographic
module.
You need to install the software and hardware for this hardware token before
installing and configuring the subsystems. You will also setup the hardware token
for use with CMS after installing CMS, but before installing a subsystem. Use the
hardware token to create subsystem certificates during installation of each
subsystem.
Protection of Private and Secret Keys
CMS certificate private keys and secret keys are to be generated and stored in a
FIPS 140-1 level 3 certified hardware cryptographic token.
The CMS private (asymmetric) keys are:
•
Private key associated with the CA signing certificate.
•
Private key associated with the RA-to-CA SSL client certificate.
•
Private key associated with the OCSP Responder signing certificate.
•
Private key associated with the CA-to-DRM SSL client certificate.
•
Private key associated with the DRM transport certificate.
•
Private key associated with the CA, RA, DRM, and OCSP SSL server
certificates.
•
Private key associated with the audit log signing certificate.
•
Private key associated with the DRM storage certificate used for encrypting
user subject encryption private keys (for DRM key archival).
The CMS secret (symmetric) key is:
•
Symmetric key used to encrypt passwords for password cache (single-sign-on).
See “Password Cache,” on page 251.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...