Certificate Manager - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

machine outside the firewall. Others may have a single CA run by a single
Certificate Manager and hundreds of Registration Managers in different
geographic locations. Still others may have many different CAs or subordinate
CAs, and only a few Registration Managers.
The sections that follow explain each subsystem in detail. For descriptions of some
basic deployment options, see Chapter 4, "Planning Your Deployment".

Certificate Manager

A Certificate Manager functions as a root or subordinate certificate authority. This
subsystem issues, renews, and revokes certificates, generates certificate revocation
lists (CRLs), and can publish certificates to an LDAP directory and a file, and CRLs
to an LDAP directory, a file, and an OCSP responder. The Certificate Manager can
be configured to accept requests from end entities, Registration Managers, or both,
and can process requests either manually (that is, with the aid of a person,
identified in this document as Certificate Manager agent) or automatically (based
entirely on customizable policies and procedures).
When set up to work with a separate Registration Manager, the Certificate
Manager processes requests and returns the signed certificates to the Registration
Manager for distribution to the end entities. (For an overview of the role of
certificate authorities and related concepts of public-key cryptography, see
Appendix D of Managing Servers with Netscape Console.
Basic capabilities of the Certificate Manager (as distinct from the Registration
Manager) include the following:
Can be configured as either a root CA or a subordinate CA
Can accept certificate requests from end entities and Registration Managers
Can issue end-entity, Registration Manager, and Certificate Manager
certificates
Can issue single key-pair or dual key-pair certificates
Can notify users and administrators of approaching certificate expiration
Can notify agents of requests pending in the queue
Can renew certificates
Can revoke certificates
Can publish certificates to an LDAP directory (LDAP 2.0 or higher) and to files
Can publish CRLs to an LDAP directory (LDAP 2.0 or higher), a file, and the
Online Certificate Status Manager.
Chapter 1
Introduction to Certificate Management System
System Overview
45

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents