Managing Certificates; Issuing Certificates - Netscape CONSOLE 6.0 - MANAGING SERVERS Manual

Managing servers with netscape console
Table of Contents

Advertisement

Managing Certificates

Managing Certificates
The set of standards and services that facilitate the use of public-key cryptography
and X.509 v3 certificates in a network environment is called the public key
infrastructure (PKI). PKI management is complex topic beyond the scope of this
document. The sections that follow introduce some of the specific certificate
management issues addressed by Netscape products.

Issuing Certificates

Certificates and the LDAP Directory
Key Management
Renewing and Revoking Certificates
Registration Authorities
Issuing Certificates
The process for issuing a certificate depends on the certificate authority that issues
it and the purpose for which it will be used. The process for issuing nondigital
forms of identification varies in similar ways. For example, if you want to get a
generic ID card (not a driver's license) from the Department of Motor Vehicles in
California, the requirements are straightforward: you need to present some
evidence of your identity, such as a utility bill with your address on it and a
student identity card. If you want to get a regular driving license, you also need to
take a test—a driving test when you first get the license, and a written test when
you renew it. If you want to get a commercial license for an eighteen-wheeler, the
requirements are much more stringent. If you live in some other state or country,
the requirements for various kinds of licenses will differ.
Similarly, different CAs have different procedures for issuing different kinds of
certificates. In some cases the only requirement may be your email address. In
other cases, your UNIX or NT login and password may be sufficient. At the other
end of the scale, for certificates that identify people who can authorize large
expenditures or make other sensitive decisions, the issuing process may require
notarized documents, a background check, and a personal interview.
Depending on an organization's policies, the process of issuing certificates can
range from being completely transparent for the user to requiring significant user
participation and complex procedures. In general, processes for issuing certificates
should be highly flexible, so organizations can tailor them to their changing needs.
260
Managing Servers with Netscape Console • December 2001

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 6.0

Table of Contents