Netscape MANAGEMENT SYSTEM 6.0 Installation And Setup Manual page 94

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.0:
Table of Contents

Advertisement

Some Enrollment Scenarios
VPN client software can use several different protocols over HTTP or HTTPS to
handle enrollment and other life-cycle management tasks. Certificate Management
System supports the Certificate Enrollment Protocol (CEP) used by Cisco routers.
CEP runs over HTTP and provides its own form of encryption.
The following steps explain how VPN client software can use the Registration
Manager and Certificate Manager to enroll in a PKI and what happens when the
client's certificate is revoked. These steps are shown in Figure 2-6.
Enroll in PKI. The VPN client sends a certificate request to the Registration
1.
Manager via CEP, and the Registration Manager processes the request and
forwards it to the Certificate Manager inside the firewall. (Any of the
authentication methods discussed in the previous sections can be used during
enrollment to authenticate the client.)
Issue certificate. The Certificate Manager issues the certificate, and the
2.
Registration Manager delivers it to the VPN client. The VPN client can now
authenticate itself to the VPN hardware and establish an encrypted channel
using IPKMP or IPSec. All TCP/IP communication passes through this
encrypted channel. From the point of view of the VPN client, it appears to be
directly connected to the TCP/IP network inside the firewall.
Publish certificate. The Certificate Manager publishes the certificate to a
3.
directory (this is an optional step).
Revoke certificate. After some time has passed, the Certificate Manager agent
4.
revokes the certificate (for example, after the certificate owner leaves the
company).
Publish CRL. The Certificate Manager publishes a new CRL to the directory
5.
specified as the CRL distribution point in the original certificate.
Verify certificate. The VPN hardware checks the CRL as part of its
6.
authentication process. Certificates listed in the CRL are not authenticated, and
VPN clients presenting them cannot establish a connection.
94
Netscape Certificate Management System Installation and Setup Guide • March 2002

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.0

Table of Contents