
Online Certificate Status Manager Certificates
127
Online Certificate Status Manager. The Online Certificate Status Manager stores each Certificate
Manager's CRL in its internal database and uses the appropriate CRL to verify the revocation status of
a certificate when queried by an OCSP-compliant client.
The Certificate Manager can generate and publish CRLs whenever a certificate is revoked and at
specified intervals. Because the purpose of an OCSP responder is to facilitate immediate verification
of certificates, the Certificate Manager should publish the CRL to the Online Certificate Status
Manager every time a certificate is revoked. Publishing only at intervals means that the OCSP service
is checking an outdated CRL.
NOTE
If the CRL is large, the Certificate Manager can take a considerable amount of time to
publish the CRL.
The Online Certificate Status Manager stores each Certificate Manager's CRL in its internal database
and uses it as the CRL to verify certificates. The Online Certificate Status Manager can also use the
CRL published to an LDAP directory, meaning the Certificate Manager does not have to update the
CRLs directly to the Online Certificate Status Manager.
5.3. Online Certificate Status Manager Certificates
When the Online Certificate Status Manager is installed, the keys for the OCSP signing certificate
and SSL server certificate are created, and the certificate requests for the signing and the SSL server
certificates are made.
These requests can be submitted either to a Certificate Manager or to a third party public CA. If the
certificate is sent to a third party CA, then the certificate must be installed when it is received. If the
OCSP signing certificate is made when the subsystem is configured and it issued by a Certificate
Manager, the certificate is installed immediately; if the Certificate Setup Wizard is used, the request is
submitted to the Certificate Manager and can be retrieved when it is issued.
5.3.1. OCSP Signing Key Pair and Certificate
Every Online Certificate Status Manager has a certificate, the OCSP signing certificate, which has
a public key corresponding to the private key the Online Certificate Status Manager uses to sign
OCSP responses. The Online Certificate Status Manager's signature provides persistent proof
that the Online Certificate Status Manager has processed the request. This certificate is generated
when the Online Certificate Status Manager is configured. The default nickname for the certificate is
ocspSigningCert cert-
instance_ID
, where
instance_ID
identifies either the Online Certificate
Status Manager or the CA instance with the internal OCSP service.
5.3.2. SSL Server Key Pair and Certificate
Every Online Certificate Status Manager has at least one SSL server certificate which was generated
when the Online Certificate Status Manager was configured. The default nickname for the certificate
is
Server-Cert cert-
instance_ID
, where
instance_ID
identifies the Online Certificate Status
Manager instance name.
The Online Certificate Status Manager uses its server certificate for server-side authentication for the
Online Certificate Status Manager agent services page.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...