Online Certificate Status Manager Deployment Considerations
172
Netscape Certificate Management System Administrator’s Guide • February 2003
2.
Set up CRLs. You need to configure the Certificate Manger to issue CRLs. See
Chapter 14, “Revocation and CRLs” for details on configuring CRLs.
3.
You must configure your policies or certificate profiles to include the Authority
Information Access extension pointing to the location at which the Certificate
Manager listens for OCSP service requests (identified as the
AuthInfoAccessExt
instance in the policy framework.)
in certificates that are
issued. This extension is necessary to identify the OSCP service. If you installed
the Certificate Manager with the OSCP service on, this extension is created
with the correct information for the OSCP service in the policy framework, and
is not enabled by default. If you chose not to configure the OSCP service, you
will have to create this policy and configure it for this service.
If you installed the Certificate Manager’s with its OCSP service feature
disabled, a default policy rule (named
AuthInfoAccessExt
) is created, but it
may not have the correct attributes for adding the Authority Information
Access extension to certificates.
See Chapter 11, “Policies” for details on configuring policies, see
“AuthInfoAccessExt,” on page 510 for specific information on this policy
module.
4.
Make sure the OCSP SSL signing certificate is from a CA that is trusted by the
Certificate Manager. See “OCSP Certificates,” on page 191 for more
information.
Online Certificate Status Manager Deployment
Considerations
This section describes the decisions you make during installation that will apply to
your initial configuration of the subsystem.
Online Certificate Status Manager Certificates
When you install the Online Certificate Status Manager, the keys for the OCSP
signing certificate and SSL server certificate are created and a certificate request is
made for the signing certificate and the SSL server certificate.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...