Publishing of Certificates to a Directory
608
Netscape Certificate Management System Installation and Setup Guide • October 2001
The publishing directory is updated at these times:
•
When the Certificate Manager starts up, it publishes its CA signing certificate to
the directory.
•
When the Certificate Manager issues a new certificate (the request may
originate from Registration Managers that’re connected to the Certificate
Manager), it stores a copy of the certificate in its internal database and then
publishes the certificate to the configured directory.
•
When the Certificate Manager revokes a certificate (the request may originate
from Registration Managers that’re connected to the Certificate Manager), it
marks the copy of the certificate in its internal database as revoked and then
unpublishes or removes the revoked certificate from the configured directory.
•
When a certificate expires, the Certificate Manager can remove that certificate
from the configured directory. Note that the server doesn’t do this
automatically. You need to configure the server to run the appropriate job. For
details, see “Configuring a Subsystem to Run Automated Jobs” on page 565.
•
When the certificate revocation list is created or updated (either through the
CMS window or through the certificate-revocation feature provided in the
agent or end-entity interface), the Certificate Manager publishes that list to the
configured directory.
Table 19-1 summarizes the above-listed actions of the Certificate Manager. The
table also indicates how the Certificate Manager populates an LDAP directory, if
configured for publishing. Note that certificates (and CRLs) are published as
DER-encoded binary blobs.
Table 19-1
Details of objects published by the Certificate Manager
Object
Action and Timing
LDAP entry
LDAP attribute
End-entity
certificate
Publishing occurs when a certificate
is issued or renewed
End-entity’s
entry
userCertificate;binary
Unpublishing (removal) occurs
when a certificate is revoked or
expired
End-entity’s
entry
userCertificate;binary
CA certificate
Publishing occurs when the
Certificate Manager is started
CA’s entry
caCertificate;binary
CRL (full)
Publishing (replacement) occurs
when a new CRL is generated
CA’s entry
certificateRevocation
List;binary
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...