Certificate Manager, Data Recovery Manager, And Registration Manager - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Topology Decisions
Like a Certificate Manager, a Data Recovery Manager has special physical security
requirements, since a compromised Data Recovery Manager would have
devastating security consequences for your entire PKI. You may therefore want to
keep the Data Recovery Manager in a special locked room or building, a choice that
can affect your deployment strategy.
Certificate Manager, Data Recovery Manager,
and Registration Manager
The three CMS subsystems can be deployed in many different relationships. Figure
4-4 illustrates some of the issues involved in deploying all three subsystems by
showing the relationships among a single Certificate Manager, a single
Registration Manager, and a single Data Recovery Manager, each installed in a
different CMS instance on a different machine.
The Registration Manager handles all end-entity interactions and communicates
with the Certificate Manager and the Data Recovery Manager over HTTPS. The
Registration Manager is configured to request the end entity's private encryption
key (in encrypted form) and send it to the Data Recovery Manager during the
enrollment process. Before the Registration Manager sends the certificate request to
the Certificate Manager for processing, the Registration Manager must receive
verification from the Data Recovery Manager that the private key has been
received and stored and that it corresponds to the end entity's public key.
Only the Certificate Manager can be configured to enable or disable LDAP
publishing or to publish to separate directories. The Certificate Manager also has
the complete record of issued certificates, so that it can perform the publishing
tasks, as shown in the figure.
Many other combinations are possible. For example, the Data Recovery Manager
and the Certificate Manager might be in the same instance; there might be multiple
Registration Managers in different instances, all dealing with the same Data
Recovery Manager and Certificate Manager; or the Certificate Manager might also
handle some end-entity interactions. It's also possible to set up both Certificate
Managers and Registration Managers such that each has a hierarchy of subordinate
managers.
170
Netscape Certificate Management System Installation and Setup Guide • October 2001

Advertisement

Table of Contents
loading

Table of Contents