515
CRMF
See
Certificate Request Message Format (CRMF)
.
cross-certification
The exchange of certificates by two CAs in different certification
hierarchies, or chains. Cross-certification extends the chain of trust
so that it encompasses both hierarchies. See also
certificate authority
(CA)
.
cryptographic algorithm
A set of rules or directions used to perform cryptographic operations
such as
encryption
and
decryption
.
Cryptographic Message
Syntax (CS)
The syntax used to digitally sign, digest, authenticate, or encrypt
arbitrary messages, such as CMMF.
cryptographic module
See
PKCS #11 module
.
cryptographic service
provider (CSP)
A cryptographic module that performs cryptographic services, such
as key generation, key storage, and encryption, on behalf of software
that uses a standard interface such as that defined by PKCS #11 to
request such services.
CSP
See
cryptographic service provider (CSP)
.
D
Data Recovery Manager
An optional, independent Certificate System subsystem that manages
the long-term archival and recovery of RSA encryption keys for
end entities. A Certificate Manager can be configured to archive
end entities' encryption keys with a Data Recovery Manager before
issuing new certificates. The Data Recovery Manager is useful only
if end entities are encrypting data, such as sensitive email, that the
organization may need to recover someday. It can be used only with
end entities that support dual key pairs: two separate key pairs, one
for encryption and one for digital signatures.
Data Recovery Manager
agent
A user who belongs to a group authorized to manage agent services
for a Data Recovery Manager, including managing the request queue
and authorizing recovery operation using HTML-based administration
pages.
Data Recovery Manager
recovery agent
One of the
m of n
people who own portions of the storage key for the
Data Recovery Manager
.
Data Recovery Manager
storage key
Special key used by the Data Recovery Manager to encrypt the end
entity's encryption key after it has been decrypted with the Data
Recovery Manager's private transport key. The storage key never
leaves the Data Recovery Manager.
Data Recovery Manager
transport certificate
Certifies the public key used by an end entity to encrypt the entity's
encryption key for transport to the Data Recovery Manager. The Data
Recovery Manager uses the private key corresponding to the certified
public key to decrypt the end entity's key before encrypting it with the
storage key.
decryption
Unscrambling data that has been encrypted. See
encryption
.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...