Overview of Key Features
34
Netscape Certificate Management System Installation and Setup Guide • May 2002
Overview of Key Features
Certificate Management System has many core features:
Support for open standards
With its support for open standards, Certificate Management System gives
organizations confidence that they will be able to communicate within a
heterogeneous computing environment. Specifically, Certificate Management
System does the following:
•
Formulates, signs, and issues industry-standard X.509 version 3 public-key
certificates; version 3 certificates include extensions that make it easy to
include organization-defined attributes. This means that you can use these
certificates for extranet and Internet authentication as well.
For details on setting extensions in certificates, see Chapter 18, “Setting Up
Policies.”
•
Supports RSA public-key algorithm for signing and encryption, DSA
public-key algorithm for signing, and MD2, MD5, and SHA-1 for hashing.
•
Supports signature key lengths of up to 1024 bits (DSA) and 4096 (RSA) on
both hardware and software tokens.
•
Supports multiple message formats, such as KEYGEN/SPAC, CRMF/CMMF,
CRS/CEP/SCEP, and PKCS #10 and CMC for certificate requests. All requests
are delivered to Certificate Management System over HTTP or HTTPS; in the
case of CRS/CEP/SCEP protocol, the delivery method is always over HTTP.
For a description of the acronyms, see “Standards Summary” on page 77.
•
Supports certificate formats that encompass certificates for SSL-based client
and server authentication, secure Multipurpose Internet Mail Extensions
(S/MIME) message signing and encryption, object signing, VPN clients, and
Cisco™ routers.
•
Supports generation and publication of CRLs conforming to X.509 version 1
and 2.
•
Publishes certificates and certificate revocation lists (CRLs) to the any
LDAP-compliant directory over LDAP and HTTP/HTTPS connections. For
more information, see Chapter 19, “Setting Up LDAP Publishing.
”
•
Publishes certificates and CRLs to a flat file for importing into other resources.
For example, the sample code for Flat File CRL and certificate publisher can be
customized to store certificates and CRLs in an Oracle RDBMS
TM
. For more
information, see Chapter 20, “Publishing Certificates and CRLs to a File.”
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...