Some Enrollment Scenarios
92
Netscape Certificate Management System Installation and Setup Guide • March 2002
results from salting and hashing. When customers use the PIN to enroll in the Atlas
PKI, the PIN is automatically removed from the directory. Enrollment PINs are
therefore more reliable than passwords, which must be protected over a long
period of time.
ExampleCorp’s process involves the following steps (illustrated in Figure 2-5):
1.
Generate PINs.
The CMS administrator runs the CMS PIN Generator against
the existing directory, populating each entry with a unique PIN.
2.
Write out PIN records.
The CMS administrator uses the CMS PIN Generator to
write out PIN records for use by an out-of-band delivery mechanism.
3.
Out-of-band delivery.
The user receives the PIN via a batch mailing system,
payroll stub, invoice form, or other out-of-band delivery mechanism.
4.
Request certificate (using PIN).
The user goes to a specified Registration
Manager URL, fills in name and PIN, and submits a certificate request.
5.
Authentication (using PIN).
The Registration Manager uses the standard CMS
PIN-based directory authentication module to verify the PIN against the
directory.
6.
Request certificate.
If authentication against the directory is successful, the
Registration Manager performs policy processing and, if this succeeds,
forwards the request to the Certificate Manager.
7.
Issue certificate.
The Certificate Manager performs its own policy processing
and, if all goes well, issues the certificate.
8.
Deliver certificate.
If the Certificate Manager issues the certificate, the
Registration Manager delivers it to the end user in the same session. If the
request is unsuccessful for any reason, the Registration Manager displays a
web page to the user explaining the problem and what to do about it.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...