473
entity named in the issuer field of a certificate is always a CA.
Certificate authorities can be independent third parties or a person or
organization using certificate-issuing server software, such as Red
Hat Certificate System.
certificate-based
authentication
Authentication based on certificates and public-key cryptography. See
also
password-based authentication
.
certificate chain
A hierarchical series of certificates signed by successive certificate
authorities. A CA certificate identifies a
certificate authority (CA)
and
is used to sign certificates issued by that authority. A CA certificate
can in turn be signed by the CA certificate of a parent CA, and so on
up to a
root CA
. Certificate System allows any end entity to retrieve all
the certificates in a certificate chain.
certificate extensions
An X.509 v3 certificate contains an extensions field that permits any
number of additional fields to be added to the certificate. Certificate
extensions provide a way of adding information such as alternative
subject names and usage restrictions to certificates. A number of
standard extensions have been defined by the PKIX working group.
certificate fingerprint
A
one-way hash
associated with a certificate. The number is not part
of the certificate itself, but is produced by applying a hash function
to the contents of the certificate. If the contents of the certificate
changes, even by a single character, the same function produces
a different number. Certificate fingerprints can therefore be used to
verify that certificates have not been tampered with.
Certificate Management
Messages over
Cryptographic Message
Syntax (CMC)
Message format used to convey a request for a certificate to
a Certificate Manager. A proposed standard from the Internet
Engineering Task Force (IETF) PKIX working group. For detailed
information, see
http://www.ietf.org/internet-drafts/draft-ietf-pkix-
cmc-02.txt
.
Certificate Management
Message Formats (CMMF)
Message formats used to convey certificate requests and revocation
requests from end entities to a Certificate Manager and to send a
variety of information to end entities. A proposed standard from the
Internet Engineering Task Force (IETF) PKIX working group. CMMF
is subsumed by another proposed standard,
Certificate Management
Messages over Cryptographic Message Syntax (CMC)
. For detailed
information, see
http://www.ietf.org/internet-drafts/draft-ietf-pkix-
cmmf-02.txt
.
Certificate Manager
An independent Certificate System subsystem that acts as a
certificate authority. A Certificate Manager instance issues, renews,
and revokes certificates, which it can publish along with CRLs to an
LDAP directory. It accepts requests from end entities. See
certificate
authority (CA)
.
Certificate Manager agent
A user who belongs to a group authorized to manage agent services
for a Certificate Manager. These services include the ability to access
and modify (approve and reject) certificate requests and issue
certificates.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...