Certificate Authority Decisions
170
Netscape Certificate Management System Installation and Setup Guide • March 2002
•
CAs and Certificate Extensions
•
CA Certificate Renewal or Reissuance
CA’s Distinguished Name
The core elements of a CA consist of a signing unit and the Certificate Manager’s
own identity. The signing unit digitally signs certificates requested by end entities
that use a specified enrollment process to establish their identities. Regardless of
how related Registration Managers or Data Recovery Managers are configured,
any Certificate Manager must have its own distinguished name (DN), which is
listed in every certificate it issues.
Like any other X.509 version 3 certificate, a CA certificate binds a DN to a public
key. A DN is a series of name-value pairs that in combination uniquely identify an
entity. For example, the following DN might be used to identify a hypothetical
Certificate Manager for the Engineering department of a corporation named
Example Corporation:
cn=demoCA, o=Example Corporation, ou=Engineering,
c=US
Many combinations of name-value pairs are possible for the Certificate Manager’s
DN. The DN must be unique and readily identifiable, since any end entity can
examine it. For more information about DNs, see Managing Servers with Netscape
Console.
CA Signing Key Type and Length
If you wish, you can import the signing key and certificate used in a previous
version of CMS installation rather than generating a new signing key pair. For
information on how to do this, check the upgrading information.
If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, check this
document:
http://www.itl.nist.gov/div897/pubs/fip186.htm
.
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
(Certificate Manager CA signing keys up to 2048 bits in length are not subject to
export restrictions.)
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...