Certificate Manager and DRM
Figure 1.1. Single-Root Certificate Manager
Figure 1.1, "Single-Root Certificate Manager"
shows the relationships between a single Certificate
Manager, end entities, and a publishing directory. The Certificate Manager can publish both end-entity
certificates and CRLs to a directory.
1.3.2. Certificate Manager and DRM
In a more complex scenario, the organization requires key archival and recovery capabilities along
with the CA; for example, when encrypted mail is widely used, the organization risks data loss if it
is unable to recover encryption keys. In this case, the Certificate System deployment has both the
Certificate Manager and a DRM.
To add key storage and recovery, a DRM can be installed on the same machine or on a different
Figure 1.2, "Certificate Manager and DRM in Different Instances"
machine.
illustrates the relationship
between a DRM and a Certificate Manager. All communication between the Certificate Manager and
the DRM takes place over HTTPS.
13
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers