Overview of Key Features
Chapter
1
Introduction to Certificate Management System
35
•
Publishes CRLs to an online validation authority (or OCSP responder),
enabling real-time verification of certificates by OCSP-compliant clients. For
more information, see Chapter 21, “Setting Up an OCSP Responder.”
Separate subsystems for certificate and key operations
Certificate Management System includes four servers, the Certificate Manager,
Registration Manager, Data Recovery Manager, and Online Certificate Status Manager.
•
The Certificate Manager functions as the certificate authority (CA); it is the
entity named in the issuer field of a certificate. The Certificate Manager can
sign and revoke certificates and generate CRLs. It can accept certificate
requests directly from end entities and via Registration Managers to which it
has delegated certain certificate management functions, such as authentication
of an end entity. The Certificate Manager also maintains a database of issued
certificates so that it can track renewal, expiration, and revocation.
•
The Registration Manager is an optional component in the PKI; it is a
subordinate server to which a Certificate Manager can delegate some
certificate management functions. For example, a Registration Manager may
act as a front end to a Certificate Manager, performing tasks such as end-entity
authentication and formulation of the certificate request for the Certificate
Manager.
•
The Data Recovery Manager is an optional component in the PKI. It provides
key archival and recovery services for end users’ encryption private keys.
•
The Online Certificate Status Manager is an optional, but important
component in the PKI. It enables real-time verification of certificates issued by
one or more Certificate Managers.
For an overview of these subsystems, see “CMS Subsystems or Managers” on
page 44.
Single CA supports multiple registration authorities
Certificate Management System lets you separate the registration process from the
certificate-signing process with the help of Registration Managers. You can run
multiple Registration Managers remotely, all reporting to a single Certificate
Manager, to verify user identities and process certificate signing requests. The
remote Registration Managers forward their completed and approved requests to
the Certificate Manager for it to sign and issue the certificate automatically.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...