Privileged-User Types and Responsibilities
392
Netscape Certificate Management System Installation and Setup Guide • October 2001
7.
Copy the base-64 encoded certificate, including the
-----BEGIN
CERTIFICATE-----
and
-----END CERTIFICATE-----
marker lines, to a text
file.
The copied information should look similar to the following example:
-----BEGIN CERTIFICATE-----
MIICJzCCAZCgAwIBAgIBAzANBgkqhkiG9w0BAQQFADBCMSAwHgYDVQQKExdOZXRzY2FwZSBDb21tdW5pY2
F0aW9uczngjhnMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTk4MDgyNzE5MDAwMFoXDTk5MDIyMzE5MDA
wMnbjdgngYoxIDAeBgNVBAoTF05ldHNjYXBlIENvbW11bmljYXRpb25zMQ8wDQYDVQQLEwZQZW9wbGUxFz
AVBgoJkiaJkIsZAEBEwdzdXByaXlhMRcwFQYDVQQDEw5TdXByaXlhIFNoZXR0eTEjMCEGCSqGSIb3Dbndg
JARYUc3Vwcml5YUBuZXRzY2FwZS5jb20wXDANBgkqhkiG9w0BAQEFAANLADBIAkEAoYiYgthgtbbnjfngj
njgnagwJjAOBgNVHQ8BAf8EBAMCBLAwFAYJYIZIAYb4QgEBAQHBAQDAgCAMA0GCSq
-----END CERTIFICATE-----
8.
Save the text file and use it to store a copy of the certificate in a subsystem’s
internal database (see “Step 3. Store the Agent’s SSL Client Certificate in the
Internal Database” on page 410).
Revocation Status Checking of Agent Certificates
You can configure a Certificate Manager and Registration Manager to check the
revocation status of an agent’s certificate the server receives during SSL client
authentication. You can configure a Data Recovery Manager (or Online Certificate
Status Manager) to check the revocation status of its agents’ certificates only if you
have deployed an OCSP responder and have issued agent certificates with
Authority Information Access extension pointing to the OCSP responder. For
information about adding Authority Information Access extension to certificates,
see “Configuring Policy Rules for a Subsystem” on page 589. For information about
setting up an OCSP responder, see Chapter 21, “Setting Up an OCSP Responder.”
NOTE
The CMS configuration file (
CMS.cfg
) includes a parameter named
jss.ocspcheck.enable
, which enables you to specify whether a
CMS manager should use Online Certificate Status Protocol (OCSP)
to verify the revocation status of the certificate it receives as a part
of SSL client or server authentication (from clients or servers it
makes connections with). If you change the value of this parameter
to
true
, the CMS manager reads the Authority Information Access
extension in the certificate and verifies the revocation status of the
certificate from the OCSP responder specified in the extension.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...