
Determining Which Certificates to Install
193
10.1.1.3. SSL Server and Client Certificates
Server certificates are used for secure communications, such as SSL, and other secure functions.
Server certificates are used to authenticate themselves during operations and to encrypt data; client
certificates authenticate the client to the server.
NOTE
CAs which have a signing certificate issued by a third-party may not be able to issue
server certificates. The third-party CA may have rules in place which prohibit its
subordinates from issuing server certificates.
10.1.1.4. User Certificates
End user certificates are a subset of client certificates that are used to identify users to a server or
system. Users can be assigned certificates to use for secure communications, such as SSL, and other
functions such as encrypting email or for single sign-on. Special users, such as Certificate System
agents, can be given client certificates to access special services.
10.1.1.5. Dual-Key Pairs
Dual-key pairs are a set of two private and public keys, where one set is used for signing and one for
encryption. These dual keys are used to create dual certificates. The dual certificate enrollment form is
one of the standard forms listed in the end-entities page of the Certificate Manager.
When generating dual-key pairs, set the certificate profiles to work correctly when generating separate
certificates for signing and encryption.
10.1.1.6. Cross-Pair Certificates
The Certificate System can issue, import, and publish cross-pair CA certificates. With cross-pair
certificates, one CA signs and issues a cross-pair certificate to a second CA, and the second CA signs
and issues a cross-pair certificate to the first CA. Both CAs then store or publish both certificates as a
crossCertificatePair
entry.
Bridging certificates can be done to honor certificates issued by a CA that is not chained to the root
CA. By establishing a trust between the Certificate System CA and another CA through a cross-pair
CA certificate, the cross-pair certificate can be downloaded and used to trust the certificates issued by
the other CA.
10.1.2. Determining Which Certificates to Install
When a Certificate System subsystem is first installed and configured, the certificates necessary
to access and administer it are automatically created. These include an agent's certificate, server
certificate, and subsystem-specific certificates. These initial certificates are shown in
Table 10.1, “Initial
Subsystem Certificates”
.
Subsystem
Certificates
Certificate Manager
• CA signing certificate
• OCSP signing certificate
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...