22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

214 Lotus Security Handbook<br />

Figure 6-11 Cross-certification between two users (servers)<br />

Cross-certification between an organization and a user<br />

In this case, the cross-certification can be for a user and a whole organization or<br />

a server and an organization.<br />

Let’s assume a scenario in which the Acme and Widget organizations want to<br />

replicate a database that contains information of common interest. The Widget<br />

organization is much smaller than the Acme organization and thus doesn’t have<br />

any problems with giving access to all their servers to the Acme organization, but<br />

because Acme deals with many organizations that are competitors to Widget,<br />

they only want to give access to a specific Domino server, as per their security<br />

policy.<br />

Here, one of the organizations wants the most restrictive form of<br />

cross-certification and another organization is comfortable with the most liberal of<br />

cross-certification, in that they want one server in the Acme organization to<br />

authenticate and replicate with any server in the Widget organization. The<br />

following steps will accomplish this:<br />

1. The Acme server (Server/Acme) obtains a cross-certificate for the Widget<br />

organization certifier (/Widget) and stores it in the Acme server Personal<br />

Address Book;<br />

2. The Widget organization certifier (/Widget) obtains a cross-certificate for the<br />

Acme server (Server/Acme) and stores it in Widget's Domino Directory.<br />

As a result of this procedure, a special relationship (that is, “the Acme server and<br />

the Widget organization trust each other”) is established. This is illustrated in<br />

Figure 6-12. In this cross-certification model, the Acme server is trusted by the

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!