Setting Up a Remote OCSP Responder
710
Netscape Certificate Management System Installation and Setup Guide • October 2001
•
Check whether you’ve installed the Online Certificate Status Manager, the
OCSP responder provided with Certificate Management System. If you
haven’t, first identify a host machine for installing it and then follow the
installation instructions in Chapter 6, “Installing Certificate Management
System” to install it. During installation, note the port numbers you assign to
the Online Certificate Status Manager.
•
Check whether you have deployed any OCSP-compliant clients. If you haven’t,
determine whether you want to use the OCSP-compliant security plug-in
module for Netscape Communicator, Netscape Personal Security Manager. For
details, see “How to Get OCSP-Compliant Clients?”
•
Keep the Netscape Console login information for the Certificate Manager and
Online Certificate Status Manager handy; you’ll need this to verify or make
changes to their configuration.
•
Read section “OCSPPublisher Plug-in Module” in Chapter 6, “Publisher
Plug-in Modules” of CMS Plug-ins Guide.
•
Read “Publishing of CRLs” on page 610. Determine whether you want the
Certificate Manager to publish version 1 or version 2 CRLs to the directory. If
you decide to publish version 2 CRLs, read Chapter 4, “Certificate Extension
Plug-in Modules” of CMS Plug-ins Guide and determine the CRL extensions
you want the Certificate Manager to set; you will be required to configure the
server to set these extensions.
•
Decide whether you want to configure your Online Certificate Status Manager
to use it’s default database for CRLs or to use an LDAP directory. If you want
the Online Certificate Status Manager to use the CRL published to the
directory, make sure that the Certificate Manager is configured to publish
CRLs to an LDAP directory. For details, see Chapter 19, “Setting Up LDAP
Publishing.”
Note the following information for the directory: the host name, port number,
and port type—whether it’s an SSL or nonSSL port. The Online Certificate
Status Manager can communicate with the directory via SSL or nonSSL port.
Step 2. Install an OCSP-Compliant Client
Follow the instructions as appropriate.
•
If you don’t want to install Personal Security Manager, skip to the next step,
“Step 3. Identify the CA to the OCSP Responder” on page 711.
•
If you decided to install Personal Security Manager, follow the instructions in
section “Step 2. Install OCSP-Compliant Client” on page 696 to install it.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...