Preparing to Use SSL and TLS Encryption
Chapter
10
Using SSL and TLS with Netscape Servers
181
Since 40-bit ciphers can be broken relatively quickly, administrators whose user
communities can use stronger ciphers should disable all 40-bit ciphers if they are
concerned about access to data by eavesdroppers.
For detailed information on determining which cipher suites to use when setting
up SSL, see Appendix C, “Introduction to SSL,” which begins on page 265.
Preparing to Use SSL and TLS Encryption
All Netscape servers, as well as Netscape 4.
x
servers, support PKCS #11 and the
SSL protocol. Many Netscape servers also support TLS. Before you request
certificates and begin to exchange information securely, you’ll need to set up SSL
and TLS. If you’re using an external security device, you will also need to install a
PKCS #11 module.
Using External Security Devices
External security devices are Public Key Cryptography Standard (PKCS) #11
modules. PKCS defines the interface used for communication between SSL and
PKCS #11 modules.
A PKCS #11 module is a device, implemented in hardware or software, that
provides cryptographic services such as encryption, decryption and, in some cases,
storage of keys and certificates. All Netscape servers include a built-in software
PKCS #11 module. Other kinds of PKCS #11 modules include the FORTEZZA
module, used by the United States government, and the Litronic cryptographic
module for smart card readers.
Netscape servers can use a variety of external PKCS #11 modules provided by
different manufacturers. Before using an external module, you must install the
manufacturer’s drivers on the machine running your Netscape server.
Slots and Security Devices
A PKCS #11 module always has one or more slots. Slots can be implemented
physically in a piece of hardware or conceptually in software. Each slot in a PKCS
#11 module can contain a
security device
, the hardware or software that actually
provides cryptographic services and stores certificates and keys. For example, a
smart card reader contains one or more slots, each of which can contain a security
device called a smart card.
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...