System Overview
44
Netscape Certificate Management System Installation and Setup Guide • May 2002
End entities and CAs may be in different geographic or organizational areas or in
completely different organizations that are linked through an extranet (that is, the
extension of a company’s internal network, or intranet) to selected customers,
suppliers, and mobile employees via the Internet. CAs may include third parties
that provide services through the Internet as well as the root CAs and subordinate
CAs for individual organizations. Policies and certificate content may vary from
one organization to another. For all these reasons and many others, the
deployment and long-term management of any large-scale PKI require careful
advance planning and custom configuration.
CMS Subsystems or Managers
Certificate Management System comprises four servers (also referred to as
subsystems or CMS managers) namely:
•
Certificate Manager
•
Registration Manager
•
Data Recovery Manager
•
Online Certificate Status Manager
To meet the widest possible range of configuration requirements, Certificate
Management System permits the independent installation of these four
subsystems, and each subsystem plays a distinct role in a PKI. Each subsystem
consists of built-in, system-level components such as authentication framework for
various types of users, schedulable jobs for automating server functions, policy
framework for evaluating certificate requests and formulating certificate contents,
publishing framework for publishing certificates and CRLs to various repositories,
and logging framework for monitoring server’s activities. Certificate Management
System supports a plug-in architecture for authentication, policy, job, publishing,
and log components; for example, Java code modules can be plugged in to
authenticate user identities and to enforce certificate issuance policies.
The Certificate Manager, Registration Manager, Data Recovery Manager, and
Online Certificate Status Manager subsystems are all highly customizable and can
be installed in a variety of configurations and physical locations. Decisions about
the number of subsystems to install, where to install them, and the relationships
among them and one or more public directories affect all aspects of installation and
configuration. Some organizations may want to install a single Certificate Manager
on one machine inside the firewall and a single Registration Manager on a separate
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...