How Certificate System Works
Chapter 1
Overview
37
How Certificate System Works
CS allows you to manage certificates by providing a flexible, scalable system for issuing,
renewing, and publishing certificates; creating and publishing CRLs; and providing key
storage and retrieval capabilities.
CS Basics
CS is installed on each host running a CS subsystem. The subsystems that will be run on
that host are then installed with a default configuration. The default configuration includes
basic administrative tasks like logging, and also contains configurable plug-in modules that
are specific to each subsystem. You can set up more than one subsystem on each host, or
multiple instances of a subsystem on the same host or on different hosts.
Subsystems
The four subsystems that comprise CS are as follows:
•
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and creating
and publishing CRLs. See Chapter 3, “Certificate Manager” for complete details.
•
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate Manager
where its signed requests are processed by the Certificate Manager. See Chapter 4,
“Registration Manager” for complete details.
•
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, “OCSP Responder” for complete
details.
•
The Data Recovery Manager is an optional subsystem that provides private encryption
key storage and retrieval. See Chapter 6, “Data Recovery Manager” for complete
details.
Interfaces
Each of the subsystems contains interfaces allowing interaction with various portions of the
subsystem. All four subsystems share a common administrative interface. All four
subsystems have an agent interface specific to that subsystem allowing agents to perform
the tasks assigned to them. A Certificate Manager and a Registration Manager have an
end-entity services interface allowing end-entities to enroll in the PKI.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...