Setting Up the OCSP Responder
188
Netscape Certificate Management System Administrator’s Guide • February 2003
27.
Configuration Status.
This screen should indicate that your configuration has
been successful and that you need to create an agent for the Online Certificate
Status Manager.
Click Done to exit the Installation Wizard.
28.
You now need to create the first agent user for the Online Certificate Status
Manager. See “Agent Certificates,” on page 337 for details.
Setting Up the OCSP Responder
In order to properly set up the Online Certificate Status Manager, you must set up
the following:
1.
Configure every CA that will publish to the OCSP Responder to Publish CRLs.
See Chapter 14, “Revocation and CRLs” for complete details.
2.
Enable Publishing and set up a publisher and a publishing rule(s) to publish
CRLs to the Online Certificate Status Manager in every CA that the OCSP will
handle. See Chapter 15, “Publishing” for complete details. (You do not need to
do this if the Certificate Manager publishes to an LDAP directory and the
Online Certificated Status Manager is set up to read from that LDAP
publishing directory.)
3.
You must configure your policies or certificate profiles for every CA that will
publish to the OCSP Responder to include the Authority Information Access
extension pointing to the location at which the Certificate Manager listens for
OCSP service requests (identified as the
AuthInfoAccessExt
instance in the
policy framework.)
in certificates that are issued. This extension is necessary to
identify the OSCP service. If you installed the Certificate Manager with the
OSCP service on, this extension is created with the correct information for the
OSCP service. If you chose not to configure the OSCP service, you will have to
create this policy and configure it for this service.
If you installed the Certificate Manager’s with its OCSP service feature
disabled, a default policy rule (named
AuthInfoAccessExt
) is created, but it
may not have the correct attributes for adding the Authority Information
Access extension to certificates.
See Chapter 11, “Policies” for details on configuring policies, see
“AuthInfoAccessExt,” on page 510 for specific information on this policy
module.
4.
Configure the OCSP Responder. See “Configuring the Online Certificate Status
Manager,” on page 189. Pay close attention to configuring the following:
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...