22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 2-16 Sample PKI digital certificate enrollment process flow<br />

84 Lotus Security Handbook<br />

The enrollment process flow depicted demonstrates the exchange of sensitive<br />

user information and secrets, plus the export of the credential outside the control<br />

of the issuer. The full enrollment scenario should include processes from a<br />

corresponding information flow control subsystem. For public key credentials, the<br />

format of certificates, along with details of how the credentials are formatted,<br />

transported, and stored are important design considerations. All scenarios must<br />

be validated against existing and proposed business processes. Validation of the<br />

scenarios substantiates the architectural decisions discussed earlier.<br />

Subsequent design steps are needed to develop and map the functions of the<br />

security subsystems to Common Criteria specifications and ultimately onto the<br />

nodes and physical components.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!