Figure B.10. A Certificate Chain That cannot Be Verified
B.5. Managing Certificates
The standards and services that facilitate using public-key cryptography and X.509 v3 certificates in
a network environment is called the public-key infrastructure (PKI). The sections that follow introduce
some specific certificate management issues involved in managing the PKI.
Section B.5.1, "Issuing Certificates"
•
Section B.5.2, "Certificates and the LDAP Directory"
•
Section B.5.3, "Key Management"
•
Section B.5.4, "Revoking Certificates"
•
B.5.1. Issuing Certificates
The process for issuing a certificate depends on the CA that issues it and the purpose for which it will
be used. Issuing nondigital forms of identification varies in similar ways. The requirements to get a
library card are different than the ones to get a driver's license. Similarly, different CAs have different
Managing Certificates
503
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?