22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Note: Many of the manual tasks associated with managing a CA prior to<br />

Domino 6 are now automated when you use the CA process.<br />

Domino certificate authority administrator tasks<br />

The Domino certificate authority administrator (CAA) is responsible for these<br />

tasks:<br />

► Create and configure certifiers.<br />

► Modify certifiers. For example, only a CA administrator can edit ID re<strong>cover</strong>y<br />

information for a Notes certifier.<br />

► Add or remove Certification and Registration Authority administrators, or<br />

change the CA and RA roles assigned to users.<br />

The CAA must have at least Editor access to the master Domino Directory for the<br />

domain.<br />

As a best practice, designate at least two CAAs for each certifier. You then have<br />

a backup if one leaves the organization.<br />

Note: By default, the administrator who creates a certifier is automatically<br />

designated as both a CAA and an RA for that certifier. When you create<br />

additional CAAs, they must be assigned the RA role in order to register users.<br />

Domino Registration Authority administrator tasks<br />

A registration authority (RA) administrator registers Notes users and Domino<br />

servers, approves or denies Internet certificate requests, and, if necessary,<br />

revokes Internet certificates. While a CA administrator can also be a registration<br />

authority, the main advantage of having a separate RA role is to off load these<br />

tasks from the Domino or CA administrator. Moreover, the Domino administrator<br />

can establish one or more RAs for each certifier enabled for the CA process.<br />

An RA should approve only those requests that will be accepted by the certifier.<br />

The CA Configuration document, stored in the CA's ICL database, describes<br />

what is acceptable.<br />

Domino administrators who register Notes users should also be listed as RAs for<br />

the Notes certifier.<br />

If you are using the Web Administrator client, you need to set up a server-based<br />

certification authority to register Notes users. The Web administrator, as well as<br />

the server on which the Web Administrator database resides, must be listed as<br />

an RA for that certifier.<br />

Chapter 11. Domino/Notes 6 security features 455

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!