Some Enrollment Scenarios; Firewall Considerations - Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

Some Enrollment Scenarios

Some Enrollment Scenarios
Successful PKI deployment requires flexible and easy enrollment for end entities as
well as ongoing support for certificate life-cycle management—that is, management of
each certificate from enrollment through encryption key storage (if necessary),
renewal, and revocation. The preceding section describes the internal flow of
control among servlets, authentication modules, and policy modules in a CMS
manager (see Figure 2-1 for a summary). The examples that follow illustrate the
flexibility that the CMS architecture supports among end entities, Registration
Managers, Certificate Managers, and existing customer databases, security
systems, and directories.

Firewall Considerations

Extranet/E-Commerce: ExampleCorp
PIN Registration: Atlas Manufacturing
VPN Client Enrollment and Revocation
Router Enrollment and Revocation
For the sake of simplicity, these examples do not show the role of the Data
Recovery Manager. For more information about data recovery, see "Data Recovery
Manager" on page 48.
For more information about certificate life-cycle management, see "End Entities
and Life-Cycle Management" on page 98.
Firewall Considerations
Most of the examples that follow show a Certificate Manager inside the firewall
and a Registration Manager outside the firewall. Other variations are possible, but
this arrangement is often appropriate. These are some of the advantages:
The most sensitive elements of the deployment—the Certificate Manager,
internal databases, directories, and so on—have the additional protection of
the firewall.
The Certificate Manager can have additional physical protection, if
desired—such as storage in a locked room and agent authentication by means
of smart cards.
All communication between the Registration Manager and the Certificate
Manager takes place over SSL with mutual authentication—that is, both client
and server authentication via X.509 v3 certificates.
84
Netscape Certificate Management System Installation and Setup Guide • March 2002

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.0 and is the answer not in the manual?

This manual is also suitable for:

Certificate management system 6.0

Table of Contents