The Online Certificate Status Manager also requires at least one SSL server
certificate. For more information about the key pairs and certificates used by a
Online Certificate Status Manager, see "Online Certificate Status Manager's Key
Pairs and Certificates" on page 449.
Authentication Decisions
CMS managers use authentication modules to verify the identity of a user
requesting a service, such as certificate enrollment. For example, a user can be
prompted to provide a name and password, and the authentication module can
check a directory entry to confirm that they are correct.
Authentication is one of the essential functions of Certificate Management System.
The main purpose of a certificate is to provide a trustworthy association between
the public key of the subject and the subject's name and other attributes. Therefore
the manner in which administrators, agents, and end entities are authenticated,
especially for operations related to certificate enrollment, requires careful planning
and control throughout the lifetime of a PKI deployment.
For examples of some different approaches to authentication during certificate
enrollment, see Chapter 2, "Certificate Enrollment and Life-Cycle Management."
For a detailed overview of authentication management using Certificate
Management System, see Chapter 15, "Setting Up End-User Authentication."
Policy Decisions
CMS managers use policies to evaluate or verify incoming certificate enrollment or
management requests from end entities and to determine the outcome. For
example, in the case of certificate enrollment request, the outcome is the issued
certificate.
Decisions regarding policies depend on both the subsystem involved and your
overall topology. Whether your CA signing certificate is self-signed or not, it
represents part of a certificate hierarchy. For example, a CA may be a root CA for
subordinate CAs that issue certificates to different parts of a large organization, or
it may be one of the subordinate CAs that chain up to an internal root CA, or it may
be a linked CA that chains up to a third party.
Authentication Decisions
Chapter 4
Planning Your Deployment
183
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 and is the answer not in the manual?