
Appendix B. Introduction to Public-Key Cryptography
458
Certificate Type
Use
Example
Client SSL certificates
Used for client authentication
to servers over SSL. Typically,
the identity of the client is
assumed to be the same
as the identity of a person,
such as an employee. See
Section B.4.2.2, “Certificate-
Based Authentication”
for a
description of the way SSL
client certificates are used for
client authentication. Client SSL
certificates can also be used as
part of single sign-on.
A bank gives a customer an
SSL client certificate that allows
the bank's servers to identify
that customer and authorize
access to the customer's
accounts.
A company gives a new
employee an SSL client
certificate that allows the
company's servers to identify
that employee and authorize
access to the company's
servers.
Server SSL certificates
Used for server authentication
to clients over SSL. Server
authentication may be used
without client authentication.
Server authentication is
required for an encrypted SSL
session. For more information,
see
Section B.4.3.2, “SSL”
.
Internet sites that engage in
electronic commerce usually
support certificate-based server
authentication to establish
an encrypted SSL session
and to assure customers
that they are dealing with the
web site identified with the
company. The encrypted SSL
session ensures that personal
information sent over the
network, such as credit card
numbers, cannot easily be
intercepted.
S/MIME certificates
Used for signed and encrypted
email. As with SSL client
certificates, the identity of
the client is assumed to be
the same as the identity of a
person, such as an employee.
A single certificate may be used
as both an S/MIME certificate
and an SSL certificate; see
Section B.4.3.3, “Signed and
Encrypted Email”
. S/MIME
certificates can also be used as
part of single sign-on.
A company deploys combined
S/MIME and SSL certificates
solely to authenticate employee
identities, thus permitting
signed email and SSL
client authentication but not
encrypted email. Another
company issues S/MIME
certificates solely to sign and
encrypt email that deals with
sensitive financial or legal
matters.
CA certificates
Used to identify CAs. Client
and server software use
CA certificates to determine
what other certificates can be
trusted. For more information,
see
Section B.4.6, “How CA
Certificates Establish Trust”
.
The CA certificates stored
in Mozilla Firefox determine
what other certificates can be
authenticated. An administrator
can implement corporate
security policies by controlling
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...