AuthInfoAccessExt Plug-in Module
134
Netscape Certificate Management System Plug-Ins Guide • May 2002
If you configure a Certificate Manager to publish CRLs to an OCSP responder and
want to include the authority information access extension referencing to the
responder, you should configure an instance of this policy as follows: access
method is set to
ocsp
, name type is set to URI, and name value is set to the URL at
which the OCSP responder listens to OCSP requests. This way, OCSP-compliant
applications can verify the revocation status of certificates issued by the Certificate
Manager by accessing the validation authority using the OCSP method.
During installation, Certificate Management System automatically creates an
instance of the authority information access extension policy. See
“AuthInfoAccessExt Rule” on page 140.
Configuration Parameters of AuthInfoAccessExt
In the CMS configuration file, the
AuthInfoAccessExt
module is identified as
<subsystem>.Policy.impl.AuthInfoAccessExt.class=com.netscape.cms.
policy.AuthInfoAccessExt
, where
<subsystem>
is
ca
or
ra
(prefix identifying
the subsystem).
In the CMS window, the module is identified as
AuthInfoAccessExt
. Figure 4-2
shows how the configurable parameters for the module are displayed in the CMS
window.
NOTE
The CMS configuration file (
CMS.cfg
) includes a parameter named
jss.ocspcheck.enable
, which enables you to specify whether a
CMS manager should use Online Certificate Status Protocol (OCSP)
to verify the revocation status of the certificate it receives as a part
of SSL client or server authentication (from clients or servers it
makes connections with). If you change the value of this parameter
to
true
, the CMS manager reads the Authority Information Access
extension in the certificate and verifies the revocation status of the
certificate from the OCSP responder specified in the extension.
Summary of Contents for Certificate Management System 6.01
Page 1: ...Plug Ins Guide Netscape Certificate Management System Version6 01 May 2002...
Page 10: ...10 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 62: ...Enrollment Forms 62 Netscape Certificate Management System Plug Ins Guide May 2002...
Page 308: ...NTEventLog Plug in Module 308 Netscape Certificate Management System Plug Ins Guide May 2002...