Topology Decisions
172
Netscape Certificate Management System Installation and Setup Guide • October 2001
You can choose to install either a Certificate Manager and Data Recovery Manager
or a Registration Manager and Data Recovery Manager in a single instance. There
is not need to install a Certificate Manager and Registration Manager in the same
instance; instead, a single Certificate Manager can be configured to perform all
Registration Manager functions.
When subsystems are installed in the same instance, the connections between them
are internal. Both subsystems must share the same host name, and the overall
number of SSL server certificates can be reduced (see “Subsystem Certificate
Decisions” on page 180).
Cloned Certificate Manager
A cloned Certificate Manager is a CMS server instance that uses the same CA
signing key and certificate as another Certificate Manager, identified as the master
Certificate Manager. Each Certificate Manager issues certificates with serial
numbers in a restricted range so that all of the servers together act as a single
Certificate Authority (operating in several server processes).
Cloning requires somewhat more management and administrative effort and it
creates more potential areas where the CA could become compromised, so it
should only be used when absolutely necessary.
The advantage of cloning is the ability to distribute the Certificate Manager’s load
across several processes or even several physical machines. For a CA that has high
enrollment demand, the distribution gained from cloning allows more certificates
to be signed and issued in a given time interval.
To create a cloned Certificate Manager, you must first install and configure at least
one Certificate Manager and specify a definite upper, but no lower bound for the
serial numbers it will use. You then install or create a new instance of a Certificate
Manager (but do not configure it). Before configuring the clone, you copy the
certificate and key database files from the original Certificate Manager to the new
Certificate Manager’s configuration
(
<server_root>cert-<instance_id>/config
) directory. If these databases are
present, the Configuration Wizard will recognize that you are creating a clone and
confirm that you want to reuse the CA’s signing key and certificate (if the clone is
on the same server, you can also reuse the SSL server certificate).
If you store the CA key material on a hardware token, you will have to follow the
hardware vendor’s instructions for copying the key material to a hardware device
accessible to the clone.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...