Complete Contents
About This Guide
PART 1: Overview and Demo Installation
Chapter 1 Introduction to Certificate Management System 4.0
Chapter 2 Default Demo Installation
PART 2: Planning and Installation
Chapter 3 Planning Your Deployment
Chapter 4 Installation Worksheet
Chapter 5 Installation and Configuration
Appendix A Migrating from Certificate Server 1.x
Appendix B Certificate Extensions
Appendix C Certificate Download Specification
Appendix D Using SSL with Enterprise Server 3.x
Appendix E Export Control Information
Glossary
Previous Next Contents Index Bookshelf


Appendix E Export Control Information

This appendix describes the cryptographic operations, key lengths, and cipher suites that have received US government approval for the export version of Certificate Management System. It does not describe the US/Canadian version of Certificate Management System.

This appendix has the following sections:


Approved Export Operations and Key Sizes
Table E.1 lists all cryptographic operations available in the export version of Certificate Management System, and the key strength or algorithm strength allowed for each operation. The term export-strength is defined in SSL Cipher Suite Profiles for Export.

Table E.1 Approved export operations and key lengths

Description of cryptographic operation
Key length or algorithm strength
SSL connections: from end entity to Registration Manager [HTML forms]
export-strength SSL
SSL connections: from end entity to Registration Manager [CSR processors]
export-strength SSL
SSL connections: from Registration Manager to Certificate Manager
export-strength SSL
SSL connections: from Registration Manager to Data Recovery Manager
export-strength SSL
SSL connections: from Registration Manager to Directory
export-strength SSL
SSL connections: from Certificate Manager to Directory
export-strength SSL
SSL connections: from Netscape Console to Registration Manager, Certificate Manager, and Data Recovery Manager subsystems
export-strength SSL
Generation, verification, and storage of PQG parameters along with DSA certificates
P,G <= 4096 and Q=160 bits
Generation, signing (encryption), verifying (decryption), and storage of RSA keys for the purpose of signing/verifying X.509 digital certificates
key <= 4096 bits
Generation, signing (encryption), verifying (decryption), and storage of DSA keys for the purpose of signing/verifying X.509 digital certificates
key <= 4096 bits
Generation, signing, verifying, and storage of RSA keys for the purpose of client authentication from Registration Manager to Certificate Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of RSA keys for the purpose of client authentication from Registration Manager to Data Recovery Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of RSA keys for the purpose of client authentication from Registration Manager subsystems to Directory
key <= 4096 bits
Generation, signing, verifying, and storage of DSA keys for the purpose of client authentication from Registration Manager to Certificate Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of DSA keys for the purpose of client authentication from Registration Manager to Data Recovery Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of DSA keys for the purpose of client authentication from Registration Manager subsystems to Directory
key <= 4096 bits
Generation, signing, verifying, and storage of RSA keys for the purpose of client authentication between Registration Manager, Certificate Manager, and Data Recovery Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of DSA keys for the purpose of client authentication between Registration Manager, Certificate Manager, and Data Recovery Manager subsystems
key <= 4096 bits
Generation, signing, verifying, and storage of RSA keys for the purpose of SSL server authentication of the Registration Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Generation, signing, verifying, and storage of RSA keys for the purpose of SSL server authentication of the Certificate Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Generation, signing, verifying, and storage of RSA keys for the purpose of SSL server authentication of the Data Recovery Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Generation, signing, verifying, and storage of DSA keys for the purpose of SSL server authentication of the Registration Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Generation, signing, verifying, and storage of DSA keys for the purpose of SSL server authentication of the Certificate Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Generation, signing, verifying, and storage of DSA keys for the purpose of SSL server authentication of the Data Recovery Manager
authentication key <= 4096 bits
key exchange key <= 1024 bits

Signature and verification of CMMF/CRMF messages by Certificate Manager, Registration Manager, and Data Recovery Manager using RSA algorithm
key <= 4096 bits
Signature and verification of CMMF/CRMF messages by Certificate Manager, Registration Manager, and Data Recovery Manager using DSA algorithm
key <= 4096 bits
Transport key for Data Recovery Manager: generation, storage, and verification of RSA key for the purpose of transport of end-entity private keys to the Data Recovery Manager (unwrap of keys)
key <= 4096 bits
Long-term storage key for Data Recovery Manager: generation, storage, encryption, and decryption using RSA key for the purpose of long term storage of end-entity private keys (wrap and unwrap of keys for storage and recovery)
key <= 4096 bits
Bulk ciphers for use in encrypting key material for long term storage within Data Recovery Manager
DES-EDE3, RC2-128, RC2-40, DES
Bulk ciphers for use in encrypting key material for transport between Registration Manager and Data Recovery Manager
DES-EDE3, RC2-128, RC2-40, DES


SSL Cipher Suite Profiles for Export
Table E.2 summarizes the cipher suite profiles approved by the US government for use in the export version of Certificate Management System.

Table E.2 SSL 3.0 export-approved cipher suite profiles for Export

SSL Protocol Version
Cipher-key length (mode) and hash algorithm
SSL2
RC4-128-EXPORT40-WITH-MD5
RC2-128-CBC-EXPORT40-WITH-MD5
SSL3
RSA-WITH-RC4-40-MD5
RSA-EXPORT56-WITH-RC4-MD5
RSA-WITH-RC2-CBC-40-MD5
RSA-EXPORT56-WITH-RC2-CBC-MD5
RSA-EXPORT-WITH-DES40-CBC-SHA
RSA-EXPORT56-WITH-DES-CBC-SHA
RSA-WITH-NULL-MD5
RSA-WITH-NULL-SHA

 

© Copyright 1999 Netscape Communications Corp., a subsidiary of America Online, Inc. All rights reserved.