End Entities and Life-Cycle Management
Chapter
2
Certificate Enrollment and Life-Cycle Management
99
Access to Subsystems
Three kinds of entities can access CMS subsystems: administrators, agents, and end
entities. Administrators are responsible for the initial setup and ongoing
maintenance of the subsystems. Agents manage the day-to-day operations of each
subsystem, such as responding to requests from end entities. End entities access
Registration Manager or Certificate Manager subsystems to enroll in a PKI and to
take part in other life-cycle management operations, such as renewal or revocation.
Figure 2-8 shows the ports used by administrators, agents, and end entities. All
agent and administrator interactions with CMS subsystems occur over HTTPS.
Table 2-1
End entities, message formats, algorithms, and key pairs supported by Certificate Management
System
End entity software
Enrollment message
format over HTTP or
HTTPS
Cryptographic algorithms
No. of key pairs
Communicator 4.0 to 4.5
KEYGEN
tag
Signing and encryption:
RSA
Signing only: RSA, DSA
Single key pair
Internet Explorer 3.x and
4.x
PKCS #10
Signing and encryption:
RSA
Signing only: RSA
Single key pair
Internet Explorer 5.x
PKCS #10
Signing and encryption:
RSA
Signing only: RSA, DSA
Single or dual key
pairs
Communicator 4.7x and
Netscape 6x
CRMF and CMMF
based on new
JavaScript API
Signing and encryption:
RSA
Signing only: RSA, DSA
Single or dual key
pairs
Netscape servers
(including CMS
managers) and other
servers
PKCS #10
Signing and encryption:
RSA
Single key pair
Cisco routers (version IOS
12.04) and VPN clients
CEP
Signing and encryption:
RSA
Single key pair
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...