
Features
30
Red Hat Certificate System Administrator’s Guide • September 2005
•
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and creating
and publishing CRLs. See Chapter 3, “Certificate Manager” for complete details.
•
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate Manager
in which its signed requests are processed. See Chapter 4, “Registration Manager” for
complete details.
•
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, “OCSP Responder” for complete
details.
•
The Data Recovery Manager is an optional subsystem that provides private encryption
key storage and retrieval. See Chapter 6, “Data Recovery Manager” for complete
details.
Certificate Manager Flexibility and Scalability
The Certificate Manager can be deployed in several ways to provide flexibility in your PKI.
Features include:
•
support for multiple registration authorities tied to a single CA
•
the ability to act as a root or subordinate CA
•
high-availability cloning to allow CAs with identical functionality, keys and
certificates to issue certificates with different sets of serial numbers.
Single CA Supports Multiple Registration Authorities
CS lets you separate the registration process from the certificate-signing process with the
help of Registration Managers. You can run multiple Registration Managers remotely, all
reporting to a single Certificate Manager, to verify user identities and process certificate
issuance, renewal, and revocation requests. The remote Registration Managers forward
their completed and approved requests to the Certificate Manager for it to sign and issue the
certificate automatically.
The Certificate Manager’s ability to support multiple Registration Managers makes it more
scalable and also adds an extra layer of security for the CA. For example, you can set a
policy that requires all clients to go through a remote Registration Manager, and then have
the remote Registration Manager route all client requests to the Certificate Manager located
inside a firewall.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...