Chapter 11. Managing Certificates
226
This list is not exhaustive; there are certificate enrollment forms for dual-use certificates for LDAP
directories, file-signing certificates, and other subsystem certificates. These forms are available
through the Certificate Manager's end-entities page, at
https://
hostname:SSLport
/ca/ee/ca
.
For more detailed information about the different certificates that can be created, see the
Certificate
System Agent's Guide
.
When the different Certificate System subsystems are installed, the basic required certificates and
keys are generated; for example, configuring the Certificate Manager generates the CA signing
certificate for the self-signed root CA, the internal OCSP signing certificate, and the SSL server
certificate and agent user certificate. Configuring the DRM generates the storage, transport, and agent
certificates. Additional certificates can be created and installed separately. The default certificates
created for each subsystem type are listed in
Section 2.3.2, “Default Settings”
. Common certificate
types are explained in the following sections.
•
Section 11.1.1.1, “CA Signing Certificates”
•
Section 11.1.1.2, “Other Signing Certificates”
•
Section 11.1.1.3, “SSL Server and Client Certificates”
•
Section 11.1.1.4, “User Certificates”
•
Section 11.1.1.5, “Dual-Key Pairs”
•
Section 11.1.1.6, “Cross-Pair Certificates”
11.1.1.1. CA Signing Certificates
Every Certificate Manager has a CA signing certificate with a public/private key pair it uses to sign the
certificates and CRLs it issues. This certificate is created and installed when the Certificate Manager is
installed.
The Certificate Manager's status as a root or subordinate CA is determined by whether its CA signing
certificate is self-signed or is signed by another CA. Self-signed root CAs set the policies they use to
issue certificates, such as the subject names, types of certificates that can be issued, and to whom
certificates can be issued. A subordinate CA has a CA signing certificate signed by another CA,
usually the one that is a level above in the CA hierarchy (which may or may not be a root CA). If the
Certificate Manager is a subordinate CA in a CA hierarchy, the root CA's signing certificate must
be imported into individual clients and servers before the Certificate Manager can be used to issue
certificates to them.
The CA certificate must be installed in a client if a server or user certificate issued by that CA is
installed on that client. The CA certificate confirms that the server certificate can be trusted. Ideally,
the certificate chain is installed. For more information on CA chains and hierarchies, see
Chapter 4,
Certificate Manager
.
11.1.1.2. Other Signing Certificates
Other services, such as the OCSP responder service and CRL publishing, can use signing certificates
other than the CA certificate. For example, a separate CRL signing certificate can be used to sign the
revocation lists that are published by a CA instead of using the CA signing certificate.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...