Introduction to Authentication
514
Netscape Certificate Management System Installation and Setup Guide • October 2001
2.
Upon receiving the certificate, the Registration Manager performs the
following authentication and authorization process:
❍
First, it verifies that the certificate exists in its internal database. Next, it
verifies that the certificate is a valid client certificate. If the certificate is
valid, the Registration Manager proceeds. Otherwise (for example, if the
certificate has expired or been revoked or was signed by an untrusted
authority), the Registration Manager rejects the request, sends an error
message to the agent, and logs a reason for the rejection.
Note that the Registration Manager verifies the revocation status of the
agent certificate if it has been issued by the Certificate Manager to which
the Registration Manager is connected to; the Certificate Manager keeps a
record of all the certificates it has issued and their current status in its
internal database. However, if the agent certificate is issued by any other
CA, the Registration Manager cannot verify the revocation status of the
certificate; it can only verify that the certificate is valid and that it has been
issued by a CA that the Registration Manager trusts. For details on
configuring the Certificate Manager or Registration Manager to check the
revocation status of its agents’ certificates, see “Revocation Status
Checking of Agent Certificates” on page 392.
If the internal database contains an invalid certificate for an agent, the
server rejects all requests from that agent. For the server to accept requests
from that agent, you would have to replace the agent’s invalid certificate in
the internal database with a valid one. For details on how to do this, see
“Changing a Privileged User’s Certificate” on page 430.
❍
The Registration Manager reads the user’s subject name (in DN form) and
the issuer name from the certificate. This combination is unique. It then
finds the login name corresponding to this unique combination in its
privileged-users list, which is stored in the internal database. If a login
name is associated with the certificate, the Registration Manager proceeds.
Otherwise, it rejects the request.
The Registration Manager then checks the group memberships of the login
name and the corresponding access rights to determine whether the user is
authorized to perform the requested service.
If both authentication and authorization succeed, the Registration Manager
services the request. Otherwise, it rejects the request and logs a reason for the
rejection.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...