![]() ![]() Certificate Authorities: How Valuable Are They? Netscape Communications Corp.'s Certificate Server 1.0 Ever get the feeling--and this applies to many vendors' wares--that products considered beta should really be called alpha, and that version 1.0 products more aptly should be viewed as beta? Netscape's Certificate Server 1.0 is one such example. It runs on several platforms, though we chose to evaluate it solely on the Intel-Windows NT platform. Installation was a bit rough and definitely confusing; we had to keep track of multiple user names and a significant number of passwords, and we were forced to run obscure key-generating commands from the DOS shell. This was not a big deal, but it makes you wonder why half of the installation process is GUI-based and the other half runs from the command line. Another mystery was why Netscape's manuals referenced the wrong file name for the zip file, and why we had to unzip the file in the first place (what happened to the install wizard?). No Scary Surprises But such complaints aside, the server performed without any surprises and appeared to be quite stable once we had it up and running. Certificate Server relies on its Informix database for key storage and management, but the database must be running before the Certificate Server can be installed. Although we're comfortable with Informix as the database of choice, its necessity adds another layer of complexity when troubleshooting. Fortunately, nothing went wrong during our testing. Typical of any Netscape server line, most of the administration is done via the browser, and administrators get a decent set of tools. To request a certificate, users fill out an included form, which go es to the administration queue for approval over a separate, secured page. When a request is approved and a certificate is issued, the server can e-mail the administrator with a URL of where to pick up the certificate. From the user's perspective, dealing with the Netscape Certificate Server is like dealing with a larger public CA--the same ease of use is there. However, Certificate Server's 1.0 strength lies not in the server itself but in its potential to integrate into a fully functioning public key infrastructure (PKI). Netscape's Certificate Server interoperates with the Lightweight Directory Access Protocol (LDAP)-based Netscape Directory Server, which in turn works with the Netscape Mail Server. This trio, combined with Secure/ Multipurpose Internet Mail Extensions (S/MIME) and other e-mail capabilities expected to be included in the final release of Netscape's Communicator (the next version of Navigator), will allow Netscape to offer a significant contribution to a standards-based environment --provided all the pieces are implemented correctly.
Xcert Software's Sentry CA
Xcert is working with Fischer International Systems Corp. to create an S/MIME client that takes advantage of Fischer's smart-card products. Although Xcert doesn't have the internal product tie-ins Netscape can offer, what it does have works very well.
Frontier Technologies Corp.'s e-Lock
|
|
|
Updated March 25, 1997 |
















