pki-System access Policy

Source: Internet
Author: User
Tags ldap

pki-system access Policy <?xml:namespace prefix = o ns = "Urn:schemas-microsoft-com:office:office"/>

In the PKI system, in order to the security of the system, the various parts of PKI need to be divided into different regions, and the access strategy of the firewall is added to prevent the unnecessary service access system.

The large direction is divided into 3 regions:

1. KMC Area (intranet)

A) KMC server

b) KMC Database

c) Encryption Machine

2. CA Area (intranet)

A) Root CA server

b) level two CA server

c) CA Database server

d) Primary LDAP

3. RA Area (intranet)

A) RA server

(b) RA database

C Intranet User Management terminal (IE)

D SSL Security Authentication Gateway

e) SVS Signature Verification Server

4. External network

A) external network RA

b External Network RA Database

c) from the LDAP

d External Network user access Terminal (IE)

Access Policy

Allows the CA zone to actively access the KMC zone and obtain a key pair.

Allow the CA zone to actively access primary LDAP and send a list of CRLs in real time.

Intranet Master LDAP actively accesses the extranet from LDAP, sending a list of CRLs in real time.

Allow internal and external RA to actively access the CA and send user information.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.