Certificate Manager Flexibility And Scalability - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Features
The Certificate Manager is the subsystem that provides Certificate Authority
functionality for issuing, renewing, revoking, and publishing certificates and
creating and publishing CRLs. See Chapter 3, "Certificate Manager" for
complete details.
The Registration Manager is an optional subsystem that provides Registration
Authority functionality. It establishes a trusted relationship with a Certificate
Manager in which its signed requests are processed. See Chapter 4,
"Registration Manager" for complete details.
The Online Certificate Status Manager is an optional subsystem that provides
stand-alone OCSP responder services. See Chapter 5, "OCSP Responder" for
complete details.
The Data Recovery Manager is an optional subsystem that provides private
encryption key storage and retrieval. See Chapter 6, "Data Recovery Manager"
for complete details.

Certificate Manager Flexibility and Scalability

The Certificate Manager can be deployed in several ways to provide flexibility in
your PKI including support for multiple registration authorities tied to a single CA,
the ability to act as a root or subordinate CA and cloning of a CA to allow CAs with
identical functionality using the same keys and certificates but using different sets
of serial numbers for their issued certificates.
Single CA Supports Multiple Registration Authorities
CMS lets you separate the registration process from the certificate-signing process
with the help of Registration Managers. You can run multiple Registration
Managers remotely, all reporting to a single Certificate Manager, to verify user
identities and process certificate issuance, renewal, and revocation requests. The
remote Registration Managers forward their completed and approved requests to
the Certificate Manager for it to sign and issue the certificate automatically.
The Certificate Manager's ability to support multiple Registration Managers makes
it more scalable and also adds an extra layer of security for the CA. For example,
you can set a policy that requires all clients to go through a remote Registration
Manager, and then have the remote Registration Manager route all client requests
to the Certificate Manager located inside a firewall.
30
Netscape Certificate Management System Administrator's Guide • February 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents