Jobs; Dual Key Pairs; Hsms And Crypto Accelerators; Support For Open Standards - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Jobs

The Jobs feature allows you to set up automated jobs that run at defined intervals.The jobs
framework comes with default jobs that you can enable and configure. You can create
additional jobs plug-in modules using the CS SDK. See Chapter 14, "Automated Jobs" for
complete details

Dual Key Pairs

CS supports certificate generation for dual key pairs—separate key pairs for signing and
encrypting mail messages and other data. To support separate key pairs for signing and
encrypting data, CS supports generation of dual certificates for end-entities capable of
generating dual key pairs, and supports key archival for encryption keys. If a client makes a
certificate request for dual key pairs, the server issues two separate certificates. This feature
is only supported for Netscape 7.0 and later browsers.

HSMs and Crypto Accelerators

CS supports Hardware Security Modules and crypto accelerators provided by various
third-party vendors of PKCS #11 version 2.01-compliant products.
You can configure the server to use different PKCS #11 modules to generate and store key
pairs (and certificates) for the Certificate Manager, Registration Manager, and Data
Recovery Manager. Note that PKCS#11 hardware devices also provide key backup and
recovery features for backup and recovery of the key material stored on the hardware token.
Be sure to refer to the PKCS #11 vendor documentation on this subject.

Support for Open Standards

With its support for open standards, CS gives organizations confidence that they will be
able to communicate within a heterogeneous computing environment. CS supports
standards in the following ways:
Formulates, signs, and issues industry-standard X.509 version 3 public-key certificates;
version 3 certificates include extensions that make it easy to include
organization-defined attributes. This means that you can use these certificates for
extranet and Internet authentication as well.
Supports RSA public-key algorithm for signing and encryption, DSA public-key
algorithm for signing, and MD2, MD5, and SHA-1 for hashing.
Features
Chapter 1
Overview
35

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents