Public Key Infrastructure Components In An Oracle Environment - Oracle Database B10772-01 Administrator's Manual

Database
Table of Contents

Advertisement

Public Key Infrastructure in an Oracle Environment

Public Key Infrastructure Components in an Oracle Environment

Public key infrastructure (PKI) components in an Oracle environment include the
following:
Certificate Authority
A certificate authority (CA) is a trusted third party that certifies the identity of
entities, such as users, databases, administrators, clients, and servers. When an
entity requests certification, the CA verifies its identity and grants a certificate,
which is signed with the CA's private key.
Different CAs may have different identification requirements when issuing
certificates. Some CAs may verify a requester's identity with a driver's license, some
may verify identity with the requester's fingerprints, while others may require that
requesters have their certificate request form notarized.
The CA publishes its own certificate, which includes its public key. Each network
entity has a list of trusted CA certificates. Before communicating, network entities
exchange certificates and check that each other's certificate is signed by one of the
CAs on their respective trusted CA certificate lists.
Network entities can obtain their certificates from the same or different CAs. By
default, Oracle Advanced Security automatically installs trusted certificates from
VeriSign, RSA, Entrust, and GTE CyberTrust when you create a new wallet.
Oracle Application Server Certificate Authority, part of Oracle Identity
Management Infrastructure, is a new Oracle PKI component available in Oracle
Application Server 10g (9.0.4).
Certificates
A certificate is created when an entity's public key is signed by a trusted certificate
authority (CA). A certificate ensures that an entity's identification information is
correct and that the public key actually belongs to that entity.
7-6 Oracle Database Advanced Security Administrator's Guide
Certificate Authority
Certificates
Certificate Revocation Lists
Wallets
Hardware security modules
"Wallets"
See Also:
on page 7-8

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Oracle Database B10772-01 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Database advanced security 10g release 1

Table of Contents