Features
Root or Subordinate CA
CMS can function as a root CA; in this case, the server signs its own CA signing
certificate as well as other CA signing certificates, enabling you to create your own
CA hierarchy. You can also install the server to function as a subordinate CA; in this
case, the server gets its CA signing key signed by another CA in an existing CA
hierarchy. See "Self-Signed Root vs. Subordinate CA," on page 84 for complete
details.
Linked CA
CMS can function as a linked CA, chaining up to many third-party or public CAs for
validation; this provides cross-company trust, so applications can verify certificate
chains outside the company certificate hierarchy. You chain a Certificate Manager
to a third-party CA by requesting the Certificate Manager's CA signing certificate
from the third-party CA.
CA Cloning
If you don't want to create a CA hierarchy comprising root and subordinate CAs,
you can create multiple clones of a Certificate Manager and configure each clone to
issue certificates that fall within a distinct range of serial numbers. Because clone
CAs use the same CA signing key and certificate (as that of the master CA) to sign
the certificates they issue, the issuer name in all the certificates in your PKI setup are
the same (as if they've been issued by a single CA). See "Cloning a CA," on page
129 for complete details.
Interfaces
Each of the subsystems contains interfaces allowing interaction with various
portions of the subsystem. All four subsystems share a common administrative
interface. All four subsystems have an agent interface specific to that subsystem
allowing agents to perform the tasks assigned to them. A Certificate Manager and a
Registration Manager have an end-entity services interface allowing end-entities to
enroll in the PKI.
Logging
CMS produces extensive logs that record system events and errors. Logs are
configurable, allowing you to create logs for specific types of events, and for the
logging level you desire. See "Logs," on page 263 for complete details.
Chapter 1
Overview
31
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR and is the answer not in the manual?