Some Enrollment Scenarios
90
Netscape Certificate Management System Installation and Setup Guide • May 2002
For example, to get a certificate, a contractor provides an ID and password to the
Registration Manager, which uses the Kerberos system to verify them before
passing on the certificate request to the Certificate Manager. This arrangement
involves the following steps, illustrated in Figure 2-4. (The details of the existing
security system don’t matter: third-party or custom CMS authentication modules
can be used for Kerberos, NIS, and many other security systems. Extranet users can
continue to use applications based on the old security systems while they use their
certificates to take advantage of new certificate-based applications.)
1.
Request certificate.
A user of ExampleCorp’s existing extranet fills in and
submits a certificate request (over SSL) using a customized form that requires a
Kerberos ID and password.
2.
Authentication.
The Registration Manager uses a third-party authentication
module to validate the user’s identity using the existing internal Kerberos
system.
3.
Request certificate.
If authentication against Kerberos is successful, the
Registration Manager performs policy processing and, if processing is
successful, forwards the request to the Certificate Manager.
4.
Issue certificate.
The Certificate Manager performs its own policy processing
on the request and, if processing is successful, issues the certificate and delivers
it to the Registration Manager.
5.
Deliver certificate.
If the Certificate Manager issues the certificate, the
Registration Manager delivers it to the end user in the same session. If the
request is unsuccessful for any reason, the Registration Manager displays a
web page to the user explaining the problem and what to do about it.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...