Certificates and Authentication
808
Netscape Certificate Manager System Administrator’s Guide • June 2003
As shown in the next section, one of the advantages of certificate-based
authentication is that it can be used to replace the first three steps in Figure J-4 with
a mechanism that allows the user to supply just one password (which is not sent
across the network) and allows the administrator to control user authentication
centrally.
Certificate-Based Authentication
Figure J-5 shows how client authentication works using certificates and the SSL
protocol. To authenticate a user to a server, a client digitally signs a randomly
generated piece of data and sends both the certificate and the signed data across
the network. For the purposes of this discussion, the digital signature associated
with some data can be thought of as evidence provided by the client to the server.
The server authenticates the user’s identity on the strength of this evidence.
Like Figure J-4, Figure J-5 assumes that the user has already decided to trust the
server and has requested a resource, and that the server has requested client
authentication in the process of evaluating whether to grant access to the requested
resource.
Figure J-5
Using a Certificate to Authenticate a Client to a Server
Unlike the process shown in Figure J-4, the process shown in Figure J-5 requires the
use of SSL. Figure J-5 also assumes that the client has a valid certificate that can be
used to identify the client to the server. Certficate-based authentication is generally
considered preferable to password-based authentication because it is based on
wheat the user has (the private key) as well as what the user knows (the password
that protects the private key). However, it’s important to note that these two
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...