Certificates and Authentication
246
Managing Servers with Netscape Console • December 2001
evaluation process can employ a variety of standard authorization
mechanisms, potentially using additional information in an LDAP directory,
company databases, and so on. If the result of the evaluation is positive, the
server allows the client to access the requested resource.
As you can see by comparing Figure B-5 to Figure B-4, certificates replace the
authentication portion of the interaction between the client and the server. Instead
of requiring a user to send passwords across the network throughout the day,
single sign-on requires the user to enter the private-key database password just
once, without sending it across the network. For the rest of the session, the client
presents the user’s certificate to authenticate the user to each new server it
encounters. Existing authorization mechanisms based on the authenticated user
identity are not affected.
How Certificates Are Used
•
Types of Certificates
•
SSL Protocol
•
Signed and Encrypted Email
•
Form Signing
•
Single Sign-On
•
Object Signing
Types of Certificates
Five kinds of certificates are commonly used with Netscape products:
•
Client SSL certificates.
Used to identify clients to servers via SSL (client
authentication). Typically, the identity of the client is assumed to be the same
as the identity of a human being, such as an employee in an enterprise. See
“Certificate-Based Authentication,” which begins on page 244, for a
description of the way client SSL certificates are used for client authentication.
Client SSL certificates can also be used for form signing and as part of a single
sign-on solution.
Examples:
A bank gives a customer a client SSL certificate that allows the
bank’s servers to identify that customer and authorize access to the customer’s
accounts. A company might give a new employee a client SSL certificate that
allows the company’s servers to identify that employee and authorize access to
the company’s servers.
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...