Glossary
514
certificate profile
A set of configuration settings that defines a certain type of
enrollment. The certificate profile sets policies for a particular type of
enrollment along with an authentication method in a certificate profile.
Certificate Request
Message Format (CRMF)
Format used for messages related to management of X.509
certificates. This format is a subset of CMMF. See also
Certificate
Management Message Formats (CMMF)
. For detailed information,
see
ftp://ftp.isi.edu/in-notes/rfc2511.txt
.
certificate revocation list
(CRL)
As defined by the X.509 standard, a list of revoked certificates by
serial number, generated and signed by a
certificate authority (CA)
.
chain of trust
See
certificate chain
.
chained CA
See
linked CA
.
cipher
See
cryptographic algorithm
.
client authentication
The process of identifying a client to a server, such as with a name
and password or with a certificate and some digitally signed data.
See
certificate-based authentication
,
password-based authentication
,
server authentication
.
client SSL certificate
A certificate used to identify a client to a server using the SSL
protocol. See
Secure Sockets Layer (SSL)
.
CMC
See
Certificate Management Messages over Cryptographic Message
Syntax (CMC)
.
CMC Enrollment
Features that allow either signed enrollment or signed revocation
requests to be sent to a Certificate Manager using an agent's signing
certificate. These requests are then automatically processed by the
Certificate Manager.
CMMF
See
Certificate Management Message Formats (CMMF)
.
Certificate System
See
Red Hat Certificate System
,
Cryptographic Message Syntax
(CS)
.
Certificate System instance
An instance of a
Certificate System subsystem
, comprising both code
and data and treated as a discrete entity.
Certificate System
subsystem
One of the five Certificate System managers:
Certificate Manager
,
Online Certificate Status Manager,
Data Recovery Manager
, Token
Key Service, or Token Processing System.
Certificate System console
A console that can be opened for any single Certificate System
instance. A Certificate System console allows the Certificate System
administrator to control configuration settings for the corresponding
Certificate System instance.
CRL
See
certificate revocation list (CRL)
.
cross-pair certificate
A certificate issued by one CA to another CA which is then stored by
both CAs to form a circle of trust. The two CAs issue certificates to
each other, and then store both cross-pair certificates as a certificate
pair.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...