ADSS Infrastructure Server Family Overview
ADSS (Advanced Digital Signature Services) Infrastructure Server offers one or multiple trust authority services for digital certificate issuance and revocation management, certificate status provision, secure timestamp issuance & secure long-term archiving and notarisation. These may be implemented together within one server or used individually as required. Since the ADSS Server management interface is common to all there are operational savings whichever implementation is handled.
ADSS Infrastructure Server provides valuable authority services for business applications, ADSS Enterprise Servers and desktop products. ADSS Server provides authorisation decisions to access its trust services. It makes it easy to run multiple virtual services by supporting multiple service policies. ADSS Server has been designed for internal Enterprise use as well as for use by Managed Service Providers.
ADSS Infrastructure Service has been designed from ground-up for maximum flexibility, security, scalability and usability – all essential requirements for a centralised multi-application and multi-party trust server. The following diagram illustrates the broad set of features:
| Name | Description |
| Certification Services | X.509 certificates and CRLs, RFC 3280, cert revocation and recovery service |
| OCSP Services | Multi-CA & multi-key support, unique validation policy per CA |
| Timestamp Services | Multiple TSA profile & multi-key support, ability to proxy to back-end devices |
| Archiving Services | Secure archiving of signed and unsigned objects, both ETSI ES-A & LTAN formats |
| Key Lengths | 1024-bit, 2048-bit, 4096-bit RSA, and with SHA-1 and SHA-2 algorithms |
| Trust layer | Use inbuilt CA, or back-end trust service providers |
| Security layer | Strong caller authentication, secure logs, optional dual control, database integrity, alert system, usage reporting, HSM support |
| Scalability layer | J2EE application allowing scalability horizontally and vertically |
| Interfaces | XML/SOAP, RFC 2560, RFC3161, LTAN XMLERS & LTAP, HTTP/S |
| Hardware tokens | SafeNet, nCipher, USB token and any other PKCS#11 compliant device |
| Databases | SQL Server, Oracle, PostgreSQL, MySQL (others available on request) |
| Operating Systems | Windows Server, Solaris, Linux (others available on request) |