
Configuring the Online Certificate Status Manager
182
Red Hat Certificate System Administrator’s Guide • September 2005
Verify Certificate Manager and Online Certificate Status Manager
Connection
When you restart the Certificate Manager, it tries to connect to the Online Certificate Status
Manager’s end-entity SSL port. To verify that the Certificate Manager did indeed
communicate with the Online Certificate Status Manager:
1.
Enter the URL for the Online Certificate Status Manager’s Agent interface. The URL
is: h
ttps://<hostname>:<port>
.
The Online Certificate Status Manager Agent Services interface appears.
2.
In the left frame, click List Certificate Authorities.
The resulting form should show information about the Certificate Manager (CA) you
configured to publish CRls to the Online Certificate Status Manager. Note the
timestamp:
❍
The This Update and Next Update fields should now be updated with the
appropriate timestamps, indicating that the Certificate Manager did communicate
with the Online Certificate Status Manager.
❍
The Requests Served Since Startup field should show a value of zero (0),
indicating that no OCSP-compliant client has queried the Online Certificate Status
Manager yet for revocation status of a certificate.
Configure the Revocation Info Stores
The Online Certificate Status Manager stores each Certificate Manager’s CRL in its internal
database and uses it as the default CRL store for verifying the revocation status of
certificates. You can also configure the Online Certificate Status Manager to use the CRL
published to an LDAP directory, instead of the CRL in its internal database. For example, if
you’ve configured Certificate Managers to publish CRLs to LDAP directories (see Chapter
16, “Publishing”), you can configure the Online Certificate Status Manager to use the CRLs
published to these directories.
To configure the Online Certificate Status Manager to use the CRLs in its internal database
or an LDAP directory for verifying revocation status of certificate:
1.
Log in to the CS window for the Online Certificate Status Manager (see “Logging Into
the CS Console” on page 239).
2.
Select the Configuration tab.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...