
About Authorization
Chapter 9
Authorization
317
•
Data Recovery Manager Agents
group is the agent group for a Data Recovery
Manager. No members are added to this group during installation, you must add
members after installation.
•
Online Certificate Status Manager Agents group is the agent group for an Online
Certificate Status Manager. No members are added to this group during installation,
you must add members after installation.
Trusted Managers
One subsystem can allow another subsystem to communicate via its agent port and perform
certain functions for that subsystem by forming a trust between the two. The subsystem that
is trusted is called a trusted manager.
The trusted manager relationship is set up in the following way:
•
The subsystem that trusts sets up the other subsystem as a trusted manager by creating
a user ID for the subsystem, adding it to the trusted manager group, and storing its SSL
client authentication certificate.
•
The trusted manager sets up a connector to subsystem it trusts, allowing it to
communicate with the subsystem. It does this by specifying the agent services port
information for that subsystem.
Possible Trusted Relationships
The Registration Manager and Certificate Manager can function as a trusted manager; the
Data Recovery Manager and Online Certificate Status Manager cannot function as a trusted
manager. The following trusted relationships can be created:
•
A Registration Manager or a Certificate Manager as a trusted manager to a Certificate
Manager. This would usually be a Registration Manager, but a Certificate Manager
could be a trusted manager to another Certificate Manager in a cloned-CA setup. See
“Cloning a CA,” on page 127 for more information.
You can configure a Certificate Manager to delegate its end-entity interactions to a
trusted Registration Manager or Certificate Manager, for reasons of localizability
(proximity to end entities), customizability, security reasons, and CA scalability; the
Certificate Manager trusts the Registration Manager and processes all certificate
requests sent by this Registration Manager.
•
Registration Manager or a Certificate Manager as a trusted manager to a Data Recovery
Manager.
You can configure a Data Recovery Manager to delegate its end-entity interactions to a
trusted Certificate Manager or Registration Manager for security reasons; the Data
Recovery Manager trusts the Certificate Manager or Registration Manager and services
all key archival and recovery requests initiated by this subsystem.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...