System Overview
Chapter
1
Introduction to Certificate Management System
51
The end-entity data formats and transport methods shown in the figure are used to
send enrollment and other requests to the Registration Manager (indicated by a
right-pointing arrow) or to send responses back to the end entities (indicated by a
left-pointing arrow). The end-entity data formats can be summarized as follows:
•
Certificate Request Message Format (CRMF) and Certificate Management
Message Formats (CMMF).
Proposed standards from the Internet Engineering
Task Force (IETF) PKIX working group that define message formats used to
convey requests to a Registration Manager or Certificate Manager and to
return information to end entities. CMMF will be subsumed by another
proposed standard, Certificate Management Messages over Cryptographic
Message Syntax (CMC), which is also supported by Certificate Management
System.
•
Certificate Enrollment Protocol (CEP).
A certificate management protocol
jointly developed by Cisco Systems and VeriSign, Inc. CEP governs
communication between routers or VPN clients and a Registration Manager or
Certificate Manager.
•
KEYGEN tag.
An HTML tag supported by Netscape browsers that generates a
key pair stored in the client and formats an HTTP GET string to send off to a
CA as part of the enrollment process.
•
Public-Key Cryptography Standard (PKCS) #7.
An encrypted data and
message format developed by RSA Data Security to represent digital
signatures, certificate chains, and encrypted data. This format is used to deliver
certificates to end entities.
•
Public-Key Cryptography Standard (PKCS) #10.
A message format developed
by RSA Data Security for certificate requests. This format is supported by
many server products and by Microsoft Internet Explorer.
These are the standard transport methods used for all of the data formats described
above:
•
Hypertext Transport Protocol (HTTP) and Hypertext Transport Protocol
Secure (HTTPS).
Protocols used to communicate with web servers.
For more information about end-entity data formats and protocols used by
Certificate Management System, see “End Entities and Life-Cycle Management” on
page 98 and “Standards Summary” on page 77.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...