Configuring a Certificate Manager to Publish Certificates and CRLs
650
Netscape Certificate Management System Installation and Setup Guide • October 2001
2.
In the Update Frequency section, specify the interval for publishing the CRL to
the directory:
Every time a certificate is revoked, or taken off-hold.
Select this option if you
want the Certificate Manager to generate the CRL every time it revokes a
certificate. Keep in mind that the Certificate Manager attempts to publish the
CRL to the configured directory whenever the CRL is generated, in this case,
every time a certificate is revoked. Publishing a CRL can be time consuming if
the CRL is large. Configuring the Certificate Manager to publish CRLs every
time a certificate is revoked may engage the server for a considerable amount
of time; during this time, the server will not be able to service any requests it
receives and will not be able to update the directory with any changes it
receives.
Update at this frequency.
Select this option if you want the Certificate
Manager to generate CRLs at regular intervals. In this case, the server
publishes the CRL to the configured directory at the interval you specify.
In the adjoining text field, type the interval, in minutes, at which the Certificate
Manager should publish CRLs. For example, if you want the server to publish
CRLs every day, you should type 1440 in this field.
with a skew of.
If you configure the server to update the CRL automatically
every time period, the server by default adds a 5 second skew to the next
update time to allow time to create the CRL and publish it. For example, if you
configure the server to update the CRL every 20 minutes, and if the CRL is
updated at 16:00:00, the CRL will be updated again at 16:19:55. You can
configure the skew by changing the default value, which is specified in
seconds.
3.
In the CRL Cache section, specify whether to enable CRL caching:
Enable cache.
Check this box to enable CRL caching. Leave the box unchecked
if you don’t want the server to maintain a cache.
Update interval.
If you enabled caching, type the interval for updating the
cache.
4.
In the CRL Format section, specify the format for publishing the CRL:
Include expired certificates.
Check this box if you want the server to include
revoked certificates that have expired in the CRL.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...