Certificate Manager Flexibility And Scalability - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Features
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and creating
and publishing CRLs. See Chapter 3, "Certificate Manager" for complete details.
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate Manager
in which its signed requests are processed. See Chapter 4, "Registration Manager" for
complete details.
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, "OCSP Responder" for complete
details.
The Data Recovery Manager is an optional subsystem that provides private encryption
key storage and retrieval. See Chapter 6, "Data Recovery Manager" for complete
details.

Certificate Manager Flexibility and Scalability

The Certificate Manager can be deployed in several ways to provide flexibility in your PKI.
Features include:
support for multiple registration authorities tied to a single CA
the ability to act as a root or subordinate CA
high-availability cloning to allow CAs with identical functionality, keys and
certificates to issue certificates with different sets of serial numbers.
Single CA Supports Multiple Registration Authorities
CS lets you separate the registration process from the certificate-signing process with the
help of Registration Managers. You can run multiple Registration Managers remotely, all
reporting to a single Certificate Manager, to verify user identities and process certificate
issuance, renewal, and revocation requests. The remote Registration Managers forward
their completed and approved requests to the Certificate Manager for it to sign and issue the
certificate automatically.
The Certificate Manager's ability to support multiple Registration Managers makes it more
scalable and also adds an extra layer of security for the CA. For example, you can set a
policy that requires all clients to go through a remote Registration Manager, and then have
the remote Registration Manager route all client requests to the Certificate Manager located
inside a firewall.
30
Red Hat Certificate System Administrator's Guide • September 2005

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents