How The Certificate Manager Works126 Netscape Certificate Management System Administrator’s Guide • June 2003Customizing the End Entity InterfaceCMS provides you with a set of forms that are available at the end entity interfaceand are preconfigured for various types of interaction with the end entity. You cancustomize this interface by changing which forms are available, and by changingthe forms themselves. You might change the look and feel of the form to fit in withyour intranet, you might change what method of authentication is associated witha form, and you might change which policies are associated with the form.Adding Data Recovery ServicesYou can set up a trusted relationship between a Data Recovery Manager and aCertificate Manager so that the end-entities’ private encryption keys are archivedduring the certificate request. See Chapter 6, “Data Recovery Manager.”How The Certificate Manager WorksThis section provides detailed information on how the Certificate Manager worksduring Enrollment, Renewal, Revocation, and Publishing of certificates and CRLsto help you better understand what configuration you will need to perform foryour PKI.EnrollmentAn end entity can enroll in your PKI by submitting an enrollment request via theend-entity interface. You can create more than one type of enrollment that eitheruses a different enrollment method, has different certificate issuance policies, orrequires a different method of authentication, or all three. You can do this bycreating separate enrollment pages that are specific to the type of enrollment, typeof authentication, and the certificate issuance policies associated with this type ofcertificate. The forms associated with enrollment are customizable allowing you tochange the content and the look and feel of the forms. See “Customizing the EndEntity Interface,” on page 126 for information on the default forms. See the NetscapeCertificate Management System Customization Guide for information on customizingthese forms. You can also do this by creating certificate profiles for each with adynamically generated form associated with each certificate profile. You customizethe dynamically created certificate profile forms by configuring the inputsassociated with the certificate profile.