
How Certificate System Works
Chapter 1
Overview
43
Publishing of Certificates
Certificates can be published to a file, an LDAP directory, or OCSP responder. You set up
the publishing feature and set up rules that determine which certificates are published using
which method, and where exactly they are published. The publishing system is flexible
allowing you many options in configuring it. If publishing is set up, a certificate is
published to the correct location(s) whenever a certificate is issued. See Chapter 16,
“Publishing” for complete details.
Key Archival
If you install a Data Recovery Manager, the private key is requested as part of enrollment
and stored in the Data Recover Manager. See Chapter 6, “Data Recovery Manager” for
complete details.
Storing Certificate Requests and Certificates
When it issues a certificate, the Certificate Manager stores both the certificate and the
certificate request in its internal database.
Renewing Certificates
A Certificate Manager allows end-entities to renew certificates if the policies are set up to
allow for renewal. If so, the end-entity submits a renewal request in the end-entity interface,
and provides the end-entities’ old certificate. The Certificate Manager will then issue a new
certificate according to the policies set.
Revoking Certificates
End-entities can submit certificate revocation requests in the end-entity interface. They
might do this if they lose their private key, or if their certificate has been otherwise
compromised. When an end-entity requests a revocation, the request is sent to the agent
services interface for agent approval.
An agent can also revoke a certificate if the owner of the certificate is unwilling or unable to
do so.
When the certificate is revoked, it is marked revoked in the internal database, and is marked
revoked in the publishing system. The certificate is also added to the Certificate Revocation
List (CRL) produced by the Certificate Manager. See Chapter 15, “Revocation and CRLs”
for complete details.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...