Features
32
Red Hat Certificate System Administrator’s Guide • September 2005
Supports Signing of Logs
CS allows you to sign log files digitally before archiving them or distributing them for audit
purposes. This feature enables you to check whether the log files were tampered with after
being signed. See “Signing Log Files,” on page 266 for complete details.
Auditing
CS can be configured to produce signed audit logs that record auditable events from the
subsystem. The audit log feature is configurable, allowing you to specify the events that are
logged. An auditor user is assigned who is the only user who can view the audit logs. This
user’s certificate is used to sign and encrypt the logs. See “Signed Audit Log,” on page 268
for complete details.
Self Tests
CS provides the framework for self-tests of the system that are automatically run at startup
and can be run on demand. It ships with a set of self tests that are configurable and allows
you to create additional self tests using the CS SDK. See “Self Tests,” on page 272 for
complete details.
Authorization
CS provides a new authorization framework that allows you to create groups and assign
access control to those groups. You can also change the default access control for prebuilt
groups, and assign access control to individual users and IP addresses. Access points for
authorization have been created for the major portions of the system allowing you to set
access control rules for each of these. You can also create additional access points and
additional access control lists using the CS SDK. See Chapter 9, “Authorization” for
complete details.
Authentication
CS provides authentication options for certificate enrollment including agent-approved
enrollment in which an agent processes the request, and several automated enrollments, in
which an authentication method is used, and upon successful authentication of the
end-entity, the CA automatically issues a certificate. CMC enrollment is also supported
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...