22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

190 Lotus Security Handbook<br />

Since Lotus Notes and Domino 6 cannot create new flat server and user IDs, it is<br />

necessary to have a Notes R4 client in order to generate new IDs.<br />

Hierarchical certificates<br />

Where hierarchical certification is concerned, the server and user IDs have only<br />

one organization certifier, and optionally up to four layers of organizational unit<br />

certifiers under the organizational certifier. When users or servers are registered<br />

with a hierarchical certifier, they receive a certificate signed by that hierarchical<br />

certifier and inherit the certification hierarchy of the layers above.<br />

For example, consider the certification hierarchy shown in Figure 6-1. This shows<br />

an organization named Acme, subdivided into three organizational units,<br />

Switzerland, USA, and UK. The USA organizational unit is subdivided into two<br />

organizational units, East and West.<br />

Figure 6-1 Hierarchical certification<br />

When registering Sandy as a new user, the Administrator of Switzerland/Acme<br />

registers her. One of the results of this process is a new, randomly-generated,<br />

RSA private/public key pair. The administrator then creates a certificate for<br />

Sandy by signing her new public key using the Switzerland/Acme certifier private<br />

key. As a result, Sandy's user ID inherits the certification hierarchy of the<br />

Switzerland/Acme certifier.<br />

In the case of Dave, it’s very similar. When registering Dave as a new user, the<br />

Administrator of West/USA/Acme registers him. One of the results of this<br />

process is a new, randomly-generated, RSA private/public key pair. The<br />

administrator then creates a certificate for Dave by signing his new public key<br />

using the West/USA/Acme certifier private key. As a result, Dave's user ID<br />

inherits the certification hierarchy of the West/USA/Acme certifier.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!