Configuring a Certificate Manager to Publish Certificates and CRLs
Chapter
19
Setting Up LDAP Publishing
661
3.
Locate the user entry for which you requested the certificate.
4.
Double-click the entry and check if the entry has a
certificate
attribute.
You should find the certificate published to the attribute. You won’t be able to
see anything interesting about the certificate; it will be a DER-encoded binary
blob.
Alternatively, you can point your browser to the user entry in the directory to
verify that the certificate has been published. To do this:
1.
Open a web browser window.
2.
In the URL field, type
ldap://<hostname>:<port>/<base_dn>??sub?(uid=<user_id>)
,
substituting
<hostname>
with the fully qualified host name of the Directory
Server,
<port_number>
with the port number at which the Directory Server is
listening to publishing requests from the Certificate Manager
<base_dn>
with
the DN to start searching for the user’s entry, and
<user_id>
with the ID of the
user to whom you issued the certificate.
For example, if the directory host name is
corpDirectory
, port number is
389
,
base DN is
O=siroe.com
, and user’s ID is
jdoe
, the URL would look like this:
ldap://corpDirectory:389/O=siroe.com??sub?(uid=jdoe)
In the resulting page, look for the user’s certificate-related information. The
information typically includes the owner of the certificate, the CA that issued
the certificate, the serial number, the validity period, and the certificate
fingerprint.
Step F. Revoke the Certificate
To check whether you’ve configured the Certificate Manager to publish the CRL to
the directory correctly, revoke the certificate you issued. In “Step A. Specify CRL
Details” on page 649, if you didn’t configure the Certificate Manager to publish the
CRL every time a certificate is revoked, go back to the Revocation List tab and
select the “Every time a certificate is revoked or taken off-hold” option. After you
complete testing, remember to go back to the same tab and uncheck the option.
To revoke the certificate:
1.
Go to the end-entity interface for the Certificate Manager (or to the Registration
Manager that’s connected to this Certificate Manager. Be sure to go to the
HTTPS interface (the revocation feature is not available in the HTTP interface).
2.
Select the Revocation tab.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...