Sie sind auf Seite 1von 11

Managing Certificates

Enroll Certificates
Secure Network Traffic by Using Certificates
Renew Certificates
Revoke Certificates
Back Up Certificates and Private Keys
Restore Certificates and Private Keys

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 1


The Certificate Enrollment Process

2 Authentication 3 Policy applied 4 Request sent to CA

6 Entity notified

1 Certificate request 7 Certificate installed 5 Certificate issued

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 2


SSL

1 Request secure connection

2 Send certificate and public key

3 Negotiate encryption

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 3


HTTPS

SSL

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 4


TLS

TCP/IP

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 5


Certificate Revocation

Private key compromised


Fraudulent certificate
Holder no longer trusted

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 6


A CRL

Revoked certificates

Contents of CRL

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 7


Private Key Protection Methods

Back up to removable media


Delete from insecure media
Require restoration password
Never share
Never transmit on network
Use key escrow

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 8


Private Key Restoration Methods

Key escrow
One or more escrow agents can restore

Key backup
Restore from backup media

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 9


The Private Key Replacement Process

1. Recover key
2. Decrypt data
3. Destroy original key
4. Obtain new key pair
5. Encrypt data with new key

Original Key Replacement Key

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 10


Reflective Questions

1. What types of certificate management functions have you


performed?

2. Which function of digital certificate management do you find the


most common? What function is the most complex?

Copyright 2005 Element K Content LLC. All rights reserved. OV 7 - 11

Das könnte Ihnen auch gefallen