Certificate Authority Decisions
Chapter
4
Planning Your Deployment
173
A cloned Certificate Manager will have all the same features, agent gateway
functions, and end entity gateway functions that a normal Certificate Manager has.
You can then configure Registration Managers that point to different Certificate
Manager servers but that appear to be serviced by the same CA.
Certificate Authority Decisions
This section covers some of the critical decisions you need to make about your
certificate authority:
•
CA’s Distinguished Name
•
CA Signing Key Type and Length
•
CA Signing Certificate’s Validity Period
•
Self-Signed Root Versus Subordinate CA
•
CAs and Certificate Extensions
•
CA Certificate Renewal or Reissuance
CA’s Distinguished Name
The core elements of a CA consist of a signing unit and the Certificate Manager’s
own identity. The signing unit digitally signs certificates requested by end entities
that use a specified enrollment process to establish their identities. Regardless of
how related Registration Managers or Data Recovery Managers are configured,
any Certificate Manager must have its own distinguished name (DN), which is
listed in every certificate it issues.
Like any other X.509 version 3 certificate, a CA certificate binds a DN to a public
key. A DN is a series of name-value pairs that in combination uniquely identify an
entity. For example, the following DN might be used to identify a hypothetical
Certificate Manager for the Engineering department of a corporation named Siroe
Corporation:
cn=demoCA, o=Siroe Corporation, ou=Engineering, c=US
Many combinations of name-value pairs are possible for the Certificate Manager’s
DN. The DN must be unique and readily identifiable, since any end entity can
examine it. For more information about DNs, see Managing Servers with Netscape
Console.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...