System Overview
Chapter
1
Introduction to Certificate Management System
45
machine outside the firewall. Others may have a single CA run by a single
Certificate Manager and hundreds of Registration Managers in different
geographic locations. Still others may have many different CAs or subordinate
CAs, and only a few Registration Managers.
The sections that follow explain each subsystem in detail. For descriptions of some
basic deployment options, see Chapter 4, “Planning Your Deployment”.
Certificate Manager
A Certificate Manager functions as a root or subordinate certificate authority. This
subsystem issues, renews, and revokes certificates, generates certificate revocation
lists (CRLs), and can publish certificates to an LDAP directory and a file, and CRLs
to an LDAP directory, a file, and an OCSP responder. The Certificate Manager can
be configured to accept requests from end entities, Registration Managers, or both,
and can process requests either manually (that is, with the aid of a person,
identified in this document as Certificate Manager agent) or automatically (based
entirely on customizable policies and procedures).
When set up to work with a separate Registration Manager, the Certificate
Manager processes requests and returns the signed certificates to the Registration
Manager for distribution to the end entities. (For an overview of the role of
certificate authorities and related concepts of public-key cryptography, see
Appendix D of Managing Servers with Netscape Console.
Basic capabilities of the Certificate Manager (as distinct from the Registration
Manager) include the following:
•
Can be configured as either a root CA or a subordinate CA
•
Can accept certificate requests from end entities and Registration Managers
•
Can issue end-entity, Registration Manager, and Certificate Manager
certificates
•
Can issue single key-pair or dual key-pair certificates
•
Can notify users and administrators of approaching certificate expiration
•
Can notify agents of requests pending in the queue
•
Can renew certificates
•
Can revoke certificates
•
Can publish certificates to an LDAP directory (LDAP 2.0 or higher) and to files
•
Can publish CRLs to an LDAP directory (LDAP 2.0 or higher), a file, and the
Online Certificate Status Manager.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...