Certificate Manager Deployment Considerations
88
Netscape Certificate Management System Administrator’s Guide • June 2003
You submit this request either as a self-signing request to the CA itself which will
then issue the certificates, this is how you create a self-signing root CA, or you
submit the request to a third party public CA and then install the certificate you
receive from the CA during the rest of the installation.
About the CA Key Pairs and Certificates
This section describes the key pairs and certificates associated with the Certificate
Manager.
CA Signing Key Pair and Certificate
Every Certificate Manager you install has a Certificate Manager CA signing certificate,
whose public key corresponds to the private key the Certificate Manager uses to
sign the X.509 certificates and CRLs it issues. This certificate is created and installed
when you install the Certificate Manager. The default nickname for the certificate is
caSigningCert cert-<instance_id>
, where
<instance_id>
identifies the CMS
instance in which the Certificate Manager is installed, and the default validity
period for the certificate is two years.
The subject name of the CA signing certificate reflects the name of your certificate
authority (CA) as specified during the installation. All certificates signed or issued
by the Certificate Manager include this name to identify the issuer of the certificate.
The Certificate Manager’s status as a root or subordinate CA is determined by
whether its CA signing certificate is self-signed or is signed by another CA.
•
If the Certificate Manager is a root CA, its CA signing certificate is
self-signed—that is, the subject name and issuer name of the certificate is the
same.
•
If the Certificate Manager is a subordinate CA, its CA signing certificate is
signed by another CA, usually the one that is a level above in the CA hierarchy
(which may or may not be a root CA). If you have deployed the Certificate
Manager as a subordinate CA in a CA hierarchy, you must import your root
CA’s signing certificate into individual clients and servers before you can use
the Certificate Manager to issue certificates to them.
NOTE
You cannot change the CA name; doing so would make all
previously issued certificates invalid. Similarly, reissuing a
Certificate Manager’s CA signing certificate with a new key pair
invalidates all certificates that have been signed by the old key pair.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...