为了改善PKI数字证书发放易用性差、集成度低和运营成本高的缺陷,在认证中心与应用系统之间引入注册代理,统一了用户数字证书发放和应用系统用户权限设置流程。给出了数字证书申请流程,基于W eb服务实现了证书发放系统,系统具有系统无关性和平台无关性。实际应用表明证书发放系统提高了PKI数字证书发放的易用性、集成度,降低了运营成本。
To improve simplicity, integration and cost of certificate issuance, this paper introduced the registry agent placed registry agent between CA and applications. Integrated certificate issuance and applications user-right assignment. It gave the certificate application proccess. It implemented the certificate issuance system based on Web services with system and platform independence. In practice, it is showed that the system impoves the simplicity, integration and cost of certificate issuance.