Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual page 46

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

System Overview
Note that the publishing tasks can be performed by the Certificate Manager only.
The Certificate Manager also has a built-in OCSP service, enabling
OCSP-compliant clients to directly query the Certificate Manager about the
revocation status of a certificate that it has issued. For example, if you plan to
deploy a PKI comprising a master CA and many clone CAs, you can enable the
OCSP service of the master CA. This way, all clients in your PKI setup can verify
the revocation status of a certificate by querying the master Certificate Manager.
The Certificate Manager can issue certificates with the following characteristics:
X.509 version 3
Internationalized subject names
Customized components in subject names
Customized extensions
The Certificate Manager supports the following signing algorithms for both
certificates and CRLs: RSA with MD2, RSA with MD5, RSA with SHA-1, and DSA
with SHA-1.
The Certificate Manager can issue X.509 v1 or v2 CRLs. A CRL can be
automatically updated whenever a certificate is revoked or at specified intervals.
CRL extensions supported include the following:
Authority key identifier. Identifies the public key to be used to validate the
digital signature on the certificate.
CRL number. A sequential number unique to each CRL issued by a given CRL
issuer. This number allows CRL-checking software to ensure that all previous
CRLs have been received.
Issuer alternative name. Associates the CRL issuer with an Internet style
identity, such as Internet electronic mail address, a DNS name, an IP address,
or a uniform resource indicator (URI).
Issuing distribution point. The URL at which this CRL is maintained.
The Delta CRL indicator extension is not supported.
CRL entry extensions supported include the following:
Hold instruction code. Indicates the action to be taken for an entry that
appears on the CRL because it has been placed on hold.
Reason code. Indicates the reason the certificate was revoked.
46
Netscape Certificate Management System Installation and Setup Guide • March 2002

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents