Online Certificate Status Manager - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Table 1-1
Key pairs used by end entities and key pairs used by the Data Recovery Manager
End-entity key pairs
Signing key pair
Public signing key:
used by recipients to
validate digital
signature
Private signing key:
used by owner to
digitally sign
messages

Online Certificate Status Manager

The Online Certificate Status Manager performs the task of an online certificate
validation authority, by enabling OCSP-compliant clients to do real-time
verification of certificates. The Online Certificate Status Manager can receive CRLs
from multiple Certificate Managers and clients can query the Online Certificate
Status Manager for the revocation status of certificates issued by all these
Certificate Managers. For example, if you plan to create a CA hierarchy comprising
a root CA and many subordinate CAs, you can configure each of these CAs to
publish their CRLs to the Online Certificate Status Manager. This way, all clients in
your PKI deployment can verify the revocation status of a certificate by querying
the Online Certificate Status Manager.
Note that an online certificate-validation authority is often referred to as an OCSP
responder.
Encryption key pair
Public encryption key:
used by others to encrypt
messages sent to owner
Private encryption key:
used by owner to decrypt
messages encrypted with
the public key
Data Recovery Manager key pairs
Transport key pair
Public transport key:
used by end-entity
software to encrypt the
end entity's private
encryption key before
sending it to Certificate
Management System for
storage.
Private transport key:
used by Data Recovery
Manager to decrypt an
end entity's private
encryption key
Chapter 1
Introduction to Certificate Management System
System Overview
Storage key pair
Public storage key:
used to decrypt an end
entity's stored private
encryption key after m of
n recovery agents have
authorized the recovery
operation.
Private storage key:
used to encrypt an end
entity's private
encryption key for
long-term storage
49

Advertisement

Table of Contents
loading

Table of Contents