Subsystem Certificate Decisions
176
Netscape Certificate Management System Installation and Setup Guide • May 2002
revocation status, without having to directly check a CRL published by a CA to the
validation authority. The validation authority, which is also called an OCSP
responder, does the checking for the application. For more information, see “What’s
an OCSP-Compliant PKI Setup?” on page 670.
To aid you in the process of setting up a OCSP-compliant PKI setup, Certificate
Management System provides two options:
•
Use the OCSP-service feature built into the Certificate Manager
•
Use the CMS OCSP responder, named Online Certificate Status Manager
Read section “How to Get an OCSP Responder?” on page 672 to decide which
method is suitable for your PKI setup.
Subsystem Certificate Decisions
Using a self-signed signing certificate for the Certificate Manager simplifies the
deployment of an initial pilot. You can install the Certificate Manager without
having to apply to a public certificate authority and waiting for it to issue, sign, and
return your CA signing certificate. Your own Certificate Manager can then issue all
the other certificates required for your pilot. However, taking this approach means
that end entities outside your organization will not recognize your Certificate
Manager unless you distribute the root Certificate Manager certificate to them.
The certificates and keys you need for each subsystem vary. Each instance requires
a separate SSL server certificate for authenticating to and commincating with
another instance.
In addition to any SSL server certificates, the Certificate Manager, Registration
Manager, and Online Certificate Status Manager each requires its own signing
certificate, and the Data Recovery Manager needs its own transport certificate and
storage key.
For more information about the key pairs and certificates used by the CMS
managers, see “Keys and Certificates for the Main Subsystems” on page 420.
SSL Server Certificates
Each CMS instance requires a single SSL server certificate.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...