Pki Operation - HP 830 Series Configuration Manual

Poe+ unified wired-wlan switch switching engine web-based
Hide thumbs Also See for HP 830 Series:
Table of Contents

Advertisement

Figure 436 PKI architecture
Entity
An entity is an end user of PKI products or services, such as a person, an organization, a device such as
a router or a switch, or a process running on a computer.
CA
A CA is a trusted authority responsible for issuing and managing digital certificates. A CA issues
certificates, specifies the validity periods of certificates, and revokes certificates as needed by publishing
CRLs.
RA
An RA is an extended part of a CA or an independent authority. An RA can implement functions
including identity authentication, CRL management, key pair generation and key pair backup. It only
examines the qualifications of users and does not sign certificates. The PKI standard recommends that an
independent RA be used for registration management to achieve a higher level of security for application
systems.
PKI repository
A PKI repository can be an LDAP server or a common database. It stores and manages information such
as certificate requests, certificates, keys, CRLs and logs, and it provides a simple query function.
LDAP is a protocol for accessing and managing PKI information. An LDAP server stores user information
and digital certificates from the RA server and provides directory navigation service. From an LDAP server,
an entity can retrieve digital certificates of its own as well as certificates of other entities.

PKI operation

In a PKI-enabled network, an entity can request a local certificate from the CA and the device can check
the validity of certificate. PKI uses the following workflow:
1.
An entity submits a certificate request to the CA.
2.
The RA verifies the identity of the entity and sends the identity information and the public key with
a digital signature to the CA.
3.
The CA verifies the digital signature, approves the application, and issues a certificate.
4.
The RA receives the certificate from the CA, sends it to the LDAP server to provide directory
navigation service, and notifies the entity that the certificate is successfully issued.
423

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents