
Cloning the Online Certificate Status Manager
662
Red Hat Certificate System Administrator’s Guide • September 2005
Cloning the Online Certificate Status Manager
Recall that CS systems may include both an OCSP service internal to the Certificate
Manager, which responds to status requests by going to the Certificate Manager’s internal
database, and a separate Online Certificate Status Manager subsystem. When you create an
OCSP clone, you are setting up a second instance of this Online Certificate Status Manager
subsystem to handle status requests based on CRLs published to it by one or more
Certificate Managers (see “Publishing of CRLs” on page 576 for more about the CRL
publishing feature). The OCSP database to which CRLs are published is replicated in the
cloned OCSP database, and requests to the Online Certificate Status Manager are, or can be,
sent to a load balancer that shares requests between the master Online Certificate Status
Manager and its clone, as Figure 17-2 illustrates.
Figure 17-2
Cloned Online Certificate Status Manager Setup
See “CS OCSP Services” on page 159 for more information about OCSP services.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...