Trusted Manager's Certificate For Ssl Client Authentication - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Connectivity service between a trusted Registration Manager and other
Figure 13-2
subsystems
Keep in mind that a trusted manager does not take on the main functions of the
subsystem that trusts it. For example, if a Registration Manager is connected to a
Certificate Manager, the Registration Manager has no authority to issue (sign)
certificates or CRLs. It receives end-entity requests, authenticates them, and
forwards them to the Certificate Manager for signing. After receiving a response
from the Certificate Manager, it notifies the end entity of the results.
Similarly, a Certificate Manager or Registration Manager connected to a Data
Recovery Manager has no authority to archive and recover end users' encryption
private keys.
You can configure a subsystem to trust one or more managers. You do this by
adding these managers as privileged users to the internal database of that
subsystem, assigning them memberships in the appropriate group, and identifying
the certificates the managers must use for SSL client authentication to the
subsystem they report to. For information about adding a trusted manager, see
"Setting Up Trusted Managers" on page 413.
During installation, Certificate Management System automatically creates a group
with trusted manager privileges. For more information about this group, see
"Group for Trusted Managers" on page 402.

Trusted Manager's Certificate for SSL Client Authentication

By default, a Registration Manager that has been set up to function as a trusted
manager uses its signing certificate for SSL client authentication to the subsystem
that trusts it. For information on this certificate, see "Signing Key Pair and
Certificate" on page 445. Similarly, a Certificate Manager that has been set up to
function as a trusted manager uses its SSL server certificate for SSL client
authentication to the subsystem that trusts it. For information on this certificate, see
"SSL Server Key Pair and Certificate" on page 441.
Privileged-User Types and Responsibilities
Chapter 13
Managing Privileged Users and Groups
397

Advertisement

Table of Contents
loading

Table of Contents