System Overview
46
Netscape Certificate Management System Installation and Setup Guide • March 2002
Note that the publishing tasks can be performed by the Certificate Manager only.
The Certificate Manager also has a built-in OCSP service, enabling
OCSP-compliant clients to directly query the Certificate Manager about the
revocation status of a certificate that it has issued. For example, if you plan to
deploy a PKI comprising a master CA and many clone CAs, you can enable the
OCSP service of the master CA. This way, all clients in your PKI setup can verify
the revocation status of a certificate by querying the master Certificate Manager.
The Certificate Manager can issue certificates with the following characteristics:
•
X.509 version 3
•
Internationalized subject names
•
Customized components in subject names
•
Customized extensions
The Certificate Manager supports the following signing algorithms for both
certificates and CRLs: RSA with MD2, RSA with MD5, RSA with SHA-1, and DSA
with SHA-1.
The Certificate Manager can issue X.509 v1 or v2 CRLs. A CRL can be
automatically updated whenever a certificate is revoked or at specified intervals.
CRL extensions supported include the following:
•
Authority key identifier.
Identifies the public key to be used to validate the
digital signature on the certificate.
•
CRL number.
A sequential number unique to each CRL issued by a given CRL
issuer. This number allows CRL-checking software to ensure that all previous
CRLs have been received.
•
Issuer alternative name.
Associates the CRL issuer with an Internet style
identity, such as Internet electronic mail address, a DNS name, an IP address,
or a uniform resource indicator (URI).
•
Issuing distribution point.
The URL at which this CRL is maintained.
The Delta CRL indicator extension is not supported.
CRL entry extensions supported include the following:
•
Hold instruction code.
Indicates the action to be taken for an entry that
appears on the CRL because it has been placed on hold.
•
Reason code.
Indicates the reason the certificate was revoked.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...