External Token; Installing External Tokens - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

Tokens for Storing CMS Keys and Certificates

External Token

An external (hardware) token refers to an external hardware device, such as a
smart card, FORTEZZA card, or other crypto card, that Certificate Management
System uses to generate and store its key pairs and certificates. Certificate
Management System supports any hardware tokens that are compliant with
PKCS#11 version 2.01. For details, see the information provided at this URL:
http://developer.netscape.com/support/faqs/pkcs_11.html
If you haven't already done so, consider using external tokens for generating and
storing the key pairs and certificates used by Certificate Management System.
These devices represent another security measure you can take to safeguard
private keys because hardware tokens are sometimes considered more secure than
software tokens. For additional details, check the literature provided by
hardware-token vendors.

Installing External Tokens

To use external encryption devices or tokens, you need to take the following steps:
Step 1. Install the Cryptographic Device
Step 2. Install the PKCS #11 Module
Step 1. Install the Cryptographic Device
To install the drivers provided by the device manufacturer, follow the instructions
that came with the device. When you install a hardware token, you are given an
opportunity to name it; be sure to use a name that will help you identify the token
later.
Step 2. Install the PKCS #11 Module
PKCS #11 is a standard set of APIs and shared libraries used by Netscape and a
number of encryption vendors. PKCS #11 isolates an application from the details of
the cryptographic device, thus enabling the application to provide a unified
interface for PKCS #11-compliant cryptographic devices.
The PKCS #11 module implemented in Certificate Management System (in
Netscape Administration Server) enables it to support cryptographic devices
supplied by many different manufacturers. Specifically, it allows Certificate
Management System to plug in shared libraries or DLLs supplied by
manufacturers of external encryption devices and use them for generating and
storing keys and certificates for the CMS managers.
432
Netscape Certificate Management System Installation and Setup Guide • March 2002

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents