About Enterprise Server Security
116
Netscape Enterprise Server Administrator’s Guide
Client and Server Authentication
Authentication
is the process of confirming an identity. In the context of
network interactions, authentication involves the confident identification of one
party by another party. Certificates are one way of supporting authentication.
Client authentication
refers to the confident identification of a client by a
server (that is, identification of the person assumed to be using the client
software).
Server authentication
refers to the confident identification of a
server by a client (that is, identification of the organization assumed to be
responsible for the server at a particular network address).
Both clients and servers can have certificates. Also, clients can have multiple
certificates, much like a person might have several different pieces of
identification. For example, if you participate in newsgroup discussions with a
Netscape Collabra Server called news.mozilla.com, you might find it possesses
a certificate issued from a company named CertSafe, assuring you that this site
is the one true news.mozilla.com. If you trust CertSafe’s judgment, then you can
trust that news.mozilla.com is the site it claims to be.
Conversely, you might be in charge of a company’s internal Human Resources
server. You could use your server’s access-control features in conjunction with
client authentication to allow only Human Resources employees access to
certain directories. For more information on access control, see “What Is Access
Control?,” in Chapter 14, “Controlling Access to Your Server.”
How Enterprise Server Uses Certificates to
Authenticate Users
Netscape servers support using client certificates to authenticate a user. There
are two basic ways the server can use a client certificate:
•
The server matches the CA in the client certificate with a trusted CA listed in
the Enterprise Administration Server. This simply ensures that the client has
a valid certificate from a CA the server trusts. (If the client is Netscape
Navigator or Netscape Communicator and the certificate is expired, the
client warns the user before sending the out-of-date certificate. Most
Netscape servers will log an error, reject the certificate, and return a
message to the client.)
Содержание Netscape Enterprise Server
Страница 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Страница 31: ...Part 1 Server Basics 31 1 Server Basics Introduction to Enterprise Server Administering Enterprise Servers ...
Страница 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Страница 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Страница 64: ...Migrating a Server From a Previous Version 64 Netscape Enterprise Server Administrator s Guide ...
Страница 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Страница 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Страница 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Страница 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Страница 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Страница 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Страница 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Страница 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Страница 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Страница 390: ...Customizing the Web Publisher User Interface 390 Netscape Enterprise Server Administrator s Guide ...
Страница 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Страница 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Страница 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Страница 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Страница 504: ...504 Netscape Enterprise Server Administrator s Guide ...