Subsystem Certificate Decisions
Chapter
4
Planning Your Deployment
181
If the Certificate Manager is acting as a root CA, the CA certificate must be installed
and trusted by each client that needs to validate certificates issued by the root
Certificate Manager. In the context of a PKI, trust refers to the relationship between
the user of a certificate and the CA that issued the certificate. If you trust a CA, you
can generally trust valid certificates issued by that CA. It’s possible to control
which CAs the client or server software trusts and which it doesn't, and for what
kinds of certificates, by means of settings within the software.
The Certificate Manager also requires an SSL server certificate. The Certificate
Manager’s SSL server certificate (or certificates) can be unique to the Certificate
Manager or, if a Data Recovery Manager is installed in the same instance, shared
with it.
In addition to these certificates, the Certificate Manager also generates a few other
certificates transparently during installation. For details, see “Certificate Manager’s
Key Pairs and Certificates” on page 437.
Registration Manager Certificates
Every Registration Manager subsystem must have a signing certificate whose
public key corresponds to the private key the Registration Manager uses to sign
end-entity certificate requests before sending them to the Certificate Manager.
Signed requests give the Certificate Manager persistent proof that a particular
Registration Manager processed the request. If the Registration Manager is set up
to publish certificates or CRLs, its signing certificate is also used for SSL client
authentication to the publishing directory (LDAP over SSL).
The Registration Manager also requires at least one SSL server certificate. The
Registration Manager’s SSL server certificate (or certificates) can be unique to the
Registration Manager or, if a Data Recovery Manager is installed in the same
instance, shared with it.
For more information about the key pairs and certificates used by a Registration
Manager, see “Registration Manager’s Key Pairs and Certificates” on page 445.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...