
Common Criteria Deployment Scenarios
Appendix C
Understanding the Common Criteria Evaluated CS Setup
701
You can configure one or more RAs to any CA you set up. You can also install a Data
Recovery Manager to any CA that you install. Though connecting a Data Recovery
Manager to a Registration Manager is one possible CS deployment scenario, it is not
currently part of the Common Criteria Evaluation. You can install and configure an OCSP
responder to any CA you install and configure, or you can have one OCSP responder work
with multiple CAs.
Features That Are Not Part of the Common Criteria
Environment
The Common Criteria Environment tests all of the features and ways of configuring CS
except for the following, which are not part of the Common Criteria Environment:
•
Using anything other than hardware tokens to create and store CIMC keys and
certificates.
•
Using the remote startup plain-text password cache,
password.conf.
•
Using the administrative interface, CS console, in non-SSL client authentication mode.
•
Cloning a Certificate Manager.
•
Connecting a Data Recovery Manager to a Registration Manager.
•
Running the internal database, or any publishing LDAP database in non-SSL client
authentication mode.
•
Using the non-profile Policy feature for enrollment.
•
Using the certificate-based authentication, face-to-face authentication (in-person
authentication) available in a Registration Manager,
•
Adding a custom plug-in, which in essence breaks the Common Criteria assurance. If
adding custom plug-ins is inevitable, it is the responsibility of all role users to carefully
evaluate these plug-ins before making them part of the system.
•
The default ACLs contain access control enforcement requirements specified in the
CIMC Security Level 3 protection profile. Caution must be taken when making
changes to them.
•
Using the internal OCSP services of a Certificate Manager.
•
CEP enrollments.
•
Challenge Revocation.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...