Ok, I see you have a lot of questions :)

An entity is a part of the PKI, a RA, CA and so forth, all of those entities are on one or more servers.
When we talk about a RA, we talk about the server a RA admin connects to, to request a certificate.


Here is an example; let’s say you have a site in Paris and one in Rome. Your administrators in Paris and Rome must generate certificates for their users.
Since you have many users in Paris and in Rome, you don’t want to mix them. You have a server in Paris called “server_paris” and you have two servers in Rome called “server_rome” and “server_main”
On each off these servers you installed the newpki server.
server_rome and server_paris can communicate with each-other thru a VPN.
server_main and server_paris can communicate with each-other thru the same VPN.
server_rome and server_main are on the same LAN.


Since your headquarter is in Rome you install the PKI entity and the CAs and a Repository on server_main:

server_main => grosseto_pki (The PKI Entity)
               grosseto_rep1 (A Repository Entity)
               grosseto_ca_root (The ROOT CA)
               grosseto_ca_smime (The S/MIME CA)

Now we create a RA entity and a Repository entity on server_rome:
server_rome => grosseto_ra_rome
               grosseto_rep2

Now we create a RA entity and a Repository entity on server_paris:
server_rome => grosseto_ra_paris
               grosseto_rep3

We link the entities like this:
grosseto_pki <-> grosseto_rep1 (Propagates the PKI conf to the other entities)
grosseto_ca_root <-> grosseto_ rep1 (Allows grosseto_ca_root to get its conf)
grosseto_ca_smime <-> grosseto_ rep1 (Allows grosseto_ca_smime to get its conf)
grosseto_rep1 <-> grosseto_rep2 (Allow Rome to discuss with the rest of the PKI)
grosseto_rep1 <-> grosseto_rep3 (Allow Paris to discuss with the rest of the PKI)
grosseto_ra_rome <-> grosseto_rep2 (Allows grosseto_ra_rome to discuss with the rest of the PKI)
grosseto_ra_paris <-> grosseto_rep3 (Allows grosseto_ra_paris to discuss with the rest of the PKI)
grosseto_ra_rome <-> grosseto_ca_smime (Allow grosseto_ra_rome to request certs from grosseto_ca_smime)
grosseto_ra_paris <-> grosseto_ca_smime (Allow grosseto_ra_paris to request certs from grosseto_ca_smime)


If you do this you will see that your graphic looks like a web spider, and that the repositories are the nodes.

Here is the complete process when a RA Admin requests a certificate from Paris:
He first connects to grosseto_ra_paris with the newpki client. He requests a certificate:
RA Admin –request-> grosseto_ra_paris –request-> grosseto_rep3 –request-> grosseto_rep1 –request-> grosseto_ca_smime –certificate-> grosseto_rep1 –certificate-> grosseto_rep3 –certificate-> grosseto_ra_paris, from their the certificate is available for the RA Admin to get it.


Here, I hope it’s clear :) Once you have assimilated all of the above, I’ll give you into tweaking your conf to by-pass a firewall, etc.

As for the certificate number, you are not limited; you can have only one CA for 100.000 certificates, that’s not an issue.


The protocol used by the entities to “talk” between each other is ASN.1 based over SSLv3.



-- Frédéric Giudicelli http://www.newpki.org



Bud P. Bruegger wrote:
Hello everyone,

I am looking into using NewPKI and was hoping someone can help me get started.

I would like to run a central CA and run multiple RAs in remote locations. Each RA site should have several workstations on which CA requests are prepared.

I would like to ask some questions in this context:

* How would this scenario translate into entities?

- does every site need to have a single Repository Entity?
- how can I scale the CA site to process large volumes of requests? Do I add multiple CA entities for this? Is there another means of scaling?


- Should each RA site have a single RA-Entity and multiple End Entities? Or is it a single Repository Entity and multiple RA-Entitites (one for each workstation)?

* Is a Repository Entity equivalent to a MySQL instance?

* How do entities relate to the schemas?
- is a Responser Entity a CA entity?
- is a Requester Entity a RA entity?
- what kind of protocol is used for the comunications in the different schemas? SSL? what on top? something else?


* In the scenario above, would the single Repository Entity of the RA site communicate with the single Repository Entity of the CA site (directly or throught firewall)?

many thanks in advance for you kind help

-b


-------------------------------------------------------------------------------------------------


Ing. Bud P. Bruegger, Ph.D.                 [EMAIL PROTECTED]
Servizio Elaborazione Dati                    0564-488 577 (voice)
Comune di Grosseto                            0564- 21139 (fax)
Via Ginori, 43
58100 Grosseto

Collaborazione Open Source per la CIE e CNS http://www.comune.grosseto.it/cie/

Open Source in P.A.:  Non solo una buona idea,  ma una necessita'
_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]
_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to