
Issuing CRLs
293
Figure 13.1. Default CRL Issuing Point
Additional issuing points for the CRLs can be created. See
Section 13.4.1, “Configuring Issuing
Points”
for details.
There are four types of CRLs the issuing points can create, depending on the options set when
configuring the issuing point to define what the CRL will list:
•
Master CRL
, which contains the list of revoked certificates from the entire CA.
•
ARL
, an Authority Revocation List containing only revoked CA certificates.
•
CRL with expired certificates
, which includes revoked certificates that have expired in the CRL.
•
CRL from certificate profiles
, which determines the revoked certificates to include based on the
profiles used to create the certificates originally.
3. Configure the CRLs for each issuing point. See
Section 13.4.2, “Configuring CRLs for Each
Issuing Point”
for details.
4. Set up the CRL extensions which are configured for the issuing point. See
Section 13.4.3, “Setting
CRL Extensions”
for details.
5. Set up the delta CRL for an issuing point by enabling extensions for that issuing point,
DeltaCRLIndicator
or
CRLNumber
.
6. Set up the
CRLDistributionPoint
extension to include information about the issuing point.
7. Set up publishing CRLs to files, an LDAP directory, or an OCSP responder. See
Chapter 14,
Publishing
for details about setting up publishing.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...