Features
30
Red Hat Certificate System Administrator’s Guide • September 2005
•
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and creating
and publishing CRLs. See Chapter 3, “Certificate Manager” for complete details.
•
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate Manager
in which its signed requests are processed. See Chapter 4, “Registration Manager” for
complete details.
•
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, “OCSP Responder” for complete
details.
•
The Data Recovery Manager is an optional subsystem that provides private encryption
key storage and retrieval. See Chapter 6, “Data Recovery Manager” for complete
details.
Certificate Manager Flexibility and Scalability
The Certificate Manager can be deployed in several ways to provide flexibility in your PKI.
Features include:
•
support for multiple registration authorities tied to a single CA
•
the ability to act as a root or subordinate CA
•
high-availability cloning to allow CAs with identical functionality, keys and
certificates to issue certificates with different sets of serial numbers.
Single CA Supports Multiple Registration Authorities
CS lets you separate the registration process from the certificate-signing process with the
help of Registration Managers. You can run multiple Registration Managers remotely, all
reporting to a single Certificate Manager, to verify user identities and process certificate
issuance, renewal, and revocation requests. The remote Registration Managers forward
their completed and approved requests to the Certificate Manager for it to sign and issue the
certificate automatically.
The Certificate Manager’s ability to support multiple Registration Managers makes it more
scalable and also adds an extra layer of security for the CA. For example, you can set a
policy that requires all clients to go through a remote Registration Manager, and then have
the remote Registration Manager route all client requests to the Certificate Manager located
inside a firewall.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...