Managing Certificates
260
Managing Servers with Netscape Console • December 2001
Managing Certificates
The set of standards and services that facilitate the use of public-key cryptography
and X.509 v3 certificates in a network environment is called the
public key
infrastructure
(PKI). PKI management is complex topic beyond the scope of this
document. The sections that follow introduce some of the specific certificate
management issues addressed by Netscape products.
•
Issuing Certificates
•
Certificates and the LDAP Directory
•
Key Management
•
Renewing and Revoking Certificates
•
Registration Authorities
Issuing Certificates
The process for issuing a certificate depends on the certificate authority that issues
it and the purpose for which it will be used. The process for issuing nondigital
forms of identification varies in similar ways. For example, if you want to get a
generic ID card (not a driver’s license) from the Department of Motor Vehicles in
California, the requirements are straightforward: you need to present some
evidence of your identity, such as a utility bill with your address on it and a
student identity card. If you want to get a regular driving license, you also need to
take a test—a driving test when you first get the license, and a written test when
you renew it. If you want to get a commercial license for an eighteen-wheeler, the
requirements are much more stringent. If you live in some other state or country,
the requirements for various kinds of licenses will differ.
Similarly, different CAs have different procedures for issuing different kinds of
certificates. In some cases the only requirement may be your email address. In
other cases, your UNIX or NT login and password may be sufficient. At the other
end of the scale, for certificates that identify people who can authorize large
expenditures or make other sensitive decisions, the issuing process may require
notarized documents, a background check, and a personal interview.
Depending on an organization’s policies, the process of issuing certificates can
range from being completely transparent for the user to requiring significant user
participation and complex procedures. In general, processes for issuing certificates
should be highly flexible, so organizations can tailor them to their changing needs.
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...