Importing Certificate Chains
Appendix
F
Certificate Download Specification
747
Importing Certificate Chains
Several of the supported formats can contain multiple certificates. When the
Netscape certificate decoder encounters a collection of certificates, it handles them
as follows:
•
The first certificate is processed in a context-specific manner, which varies
according to how it is being imported. For Communicator, this handling
depends upon the MIME content type that is used on the object being
downloaded. For Netscape servers, it depends upon the options selected in the
server administration interface.
•
Subsequent certificates are all treated the same. If the certificates contain the
SSL-CA bit in the netscape-cert-type certificate extension and do not already
exist in the local certificate database, they are added as untrusted CAs. In this
way they can be used for certificate chain validation as long as there is a
trusted CA somewhere along the chain.
Importing Certificates into Netscape
Communicator
Communicator imports certificates via HTTP. There are several MIME content
types that are used to indicate to Communicator what type of certificate is being
imported. These MIME types are as follows:
•
application/x-x509-user-cert
The certificate being downloaded is a user certificate belonging to the user
operating Communicator. If the private key associated with the certificate does
not exist in the user’s local key database, then Communicator generates an
error dialog and the certificate is not imported. If a certificate chain is being
imported, then the first certificate in the chain must be the user certificate, and
any subsequent certificates will be added as untrusted CA certificates to the
local database.
•
application/x-x509-ca-cert
The certificate being downloaded represents a certificate authority. When it is
downloaded, a sequence of dialogs guides the user through the process of
accepting the Certificate Authority and deciding whether to trust sites certified
by the CA.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...