Chapter 13. Revocation and CRLs
300
Figure 13.5. CRL Extensions
4. To modify a rule, select it, and click
Edit/View
.
5. Most extensions have two options, enabling them and setting whether they are critical. Some
require more information. Supply all required values. See
Section A.5, “Standard X.509 v3
CRL Extensions”
for complete information about each extension and the parameters for those
extensions.
6. Click
OK
.
7. Click
Refresh
to see the updated status of all the rules.
13.5. Setting Full and Delta CRL Schedules
CRLs are published periodically. Setting that period is touched on in the configuration in
Section 13.4.2, “Configuring CRLs for Each Issuing Point”
.
First, CRLs are issued according to a time-based schedule. CRLs can be issued every single time a
certificate is revoked, at a specific time of day, or once every so-many minutes.
However, this time-based publishing schedule applies to every CRL that is generated. There are two
kinds of CRLs, however. The full CRL has a record of every single revoked certificate. However, the
Certificate System also publishes a delta CRL, which contains only the certificates that have been
revoked since the last CRL (delta or full) was published.
By default, full and delta CRLs are generated at the same time, and every time. However, it is
possible to space out when full CRLs are published and to publish multiple interim delta CRLs. This is
configured in the
CRL schema
, which sets the scheme for publishing delta and full CRLs.
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...