525
each other, and then store both cross-pair certificates as a certificate
pair.
CRMF
See
Certificate Request Message Format (CRMF)
.
cross-certification
The exchange of certificates by two CAs in different certification
hierarchies, or chains. Cross-certification extends the chain of trust
so that it encompasses both hierarchies. See also
certificate authority
(CA)
.
cryptographic algorithm
A set of rules or directions used to perform cryptographic operations
such as
encryption
and
decryption
.
Cryptographic Message
Syntax (CS)
The syntax used to digitally sign, digest, authenticate, or encrypt
arbitrary messages, such as CMMF.
cryptographic module
See
PKCS #11 module
.
cryptographic service
provider (CSP)
A cryptographic module that performs cryptographic services, such
as key generation, key storage, and encryption, on behalf of software
that uses a standard interface such as that defined by PKCS #11 to
request such services.
CSP
See
cryptographic service provider (CSP)
.
D
Data Recovery Manager
An optional, independent Certificate System subsystem that manages
the long-term archival and recovery of RSA encryption keys for
end entities. A Certificate Manager can be configured to archive
end entities' encryption keys with a Data Recovery Manager before
issuing new certificates. The Data Recovery Manager is useful only
if end entities are encrypting data, such as sensitive email, that the
organization may need to recover someday. It can be used only with
end entities that support dual key pairs: two separate key pairs, one
for encryption and one for digital signatures.
Data Recovery Manager
agent
A user who belongs to a group authorized to manage agent services
for a Data Recovery Manager, including managing the request queue
and authorizing recovery operation using HTML-based administration
pages.
Data Recovery Manager
recovery agent
One of the
m of n
people who own portions of the storage key for the
Data Recovery Manager
.
Data Recovery Manager
storage key
Special key used by the Data Recovery Manager to encrypt the end
entity's encryption key after it has been decrypted with the Data
Recovery Manager's private transport key. The storage key never
leaves the Data Recovery Manager.
Data Recovery Manager
transport certificate
Certifies the public key used by an end entity to encrypt the entity's
encryption key for transport to the Data Recovery Manager. The Data
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...