Ca's Distinguished Name; Ca Signing Key Type And Length - Netscape MANAGEMENT SYSTEM 6.01 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.01:
Table of Contents

Advertisement

Certificate Authority Decisions
CAs and Certificate Extensions
CA Certificate Renewal or Reissuance

CA's Distinguished Name

The core elements of a CA consist of a signing unit and the Certificate Manager's
own identity. The signing unit digitally signs certificates requested by end entities
that use a specified enrollment process to establish their identities. Regardless of
how related Registration Managers or Data Recovery Managers are configured,
any Certificate Manager must have its own distinguished name (DN), which is
listed in every certificate it issues.
Like any other X.509 version 3 certificate, a CA certificate binds a DN to a public
key. A DN is a series of name-value pairs that in combination uniquely identify an
entity. For example, the following DN might be used to identify a hypothetical
Certificate Manager for the Engineering department of a corporation named
Example Corporation:
c=US
Many combinations of name-value pairs are possible for the Certificate Manager's
DN. The DN must be unique and readily identifiable, since any end entity can
examine it. For more information about DNs, see Managing Servers with Netscape
Console.

CA Signing Key Type and Length

If you wish, you can import the signing key and certificate used in a previous
version of CMS installation rather than generating a new signing key pair. For
information on how to do this, check the upgrading information.
If you decide to generate a new signing key, one of the first decisions you need to
make is whether to use the RSA or DSA algorithm. If you use DSA, the software
can generate and verify the PQG value. PQG values are used to create the DSA
signing key pair. For more information about the way they are used, check this
document:
In general, longer keys are considered to be cryptographically stronger than
shorter keys. However, longer keys also require more time for signing operations.
(Certificate Manager CA signing keys up to 2048 bits in length are not subject to
export restrictions.)
170
Netscape Certificate Management System Installation and Setup Guide • May 2002
cn=demoCA, o=Example Corporation, ou=Engineering,
http://www.itl.nist.gov/div897/pubs/fip186.htm
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents